NSE4 System and Network Administration Practice Question
An admin needs to configure a FortiGate to send logs to a FortiAnalyzer. Which TWO steps must be performed? (Choose two.)
⚠ Common exam trap
Test-takers frequently think a firewall policy is required to allow outbound log traffic, but FortiGate management traffic (including logs to FortiAnalyzer) bypasses the firewall policy engine and is controlled solely by the management VDOM or system settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the FortiAnalyzer IP under config system log-fortianalyzer
The FortiGate must be configured with the FortiAnalyzer IP address under the `config system log-fortianalyzer` hierarchy to establish the logging destination. Option E is correct because after setting the IP, the `set status enable` command must be issued to activate log forwarding to that FortiAnalyzer; without this, no logs are sent even if the IP is configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the log aggregation interval
Why it's wrong here
Setting the log aggregation interval is an optional tuning parameter that controls how log summaries are compiled, such as hourly or daily rollups. While it can be configured under the log-fortianalyzer settings to optimize reporting, it does not establish the FortiAnalyzer connection. Without first specifying the server IP and enabling the status, no logs are forwarded regardless of aggregation settings.
- ✗
Configure SNMP trap destinations
Why it's wrong here
SNMP trap destinations are used to send SNMP alerts/notifications for network events to an SNMP manager. This is a separate logging and alerting mechanism from FortiAnalyzer log forwarding. FortiAnalyzer receives syslog-style logs via proprietary protocols, not SNMP traps. Configuring SNMP destinations would not forward firewall logs to FortiAnalyzer and is irrelevant to the required log-forwarding configuration.
- ✗
Create a firewall policy to allow traffic to FortiAnalyzer
Why it's wrong here
In some deployments, FortiAnalyzer may be on a different network segment, requiring an inter-VDOM or intra-VDOM policy to permit the log forwarding traffic. However, this is a prerequisite for network connectivity rather than the actual log configuration. The direct configuration step is to define the FortiAnalyzer server under the system log-fortianalyzer hierarchy and enable it; the firewall policy only ensures the traffic can traverse, not that logging is enabled.
- ✓
Configure the FortiAnalyzer IP under config system log-fortianalyzer
Why this is correct
The command `config system log-fortianalyzer` enters the FortiAnalyzer configuration mode, where the `set server <ip>` command specifies the IPv4 address of the FortiAnalyzer device that will receive logs. This is the mandatory first step in the CLI to point the FortiGate at its log collector. Without this address, the FortiGate has no destination for its syslog-like log streams to FortiAnalyzer. Optionally, parameters like `set upload-option` and `set source-ip` can also be set here, but the server IP is essential.
- ✓
Enable logging to FortiAnalyzer using the 'set status enable' command under the same configuration
Why this is correct
Merely specifying the FortiAnalyzer IP does not activate log forwarding; the FortiGate disables the FortiAnalyzer log link by default. Running `set status enable` within `config system log-fortianalyzer` turns on the log upload, causing the FortiGate to establish a connection and transmit logs according to the configured upload/schedule settings. This is the necessary second step that makes the configured IP operational.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.