NSE4 System and Network Administration Practice Question
An administrator is configuring a FortiGate to send logs to a FortiAnalyzer. Which TWO of the following are required? (Choose two.)
⚠ Common exam trap
Watch out — candidates often think a firewall policy is needed to allow log traffic, but FortiGate's own traffic (including logs) is not subject to firewall policies; only transit traffic requires policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure network connectivity between FortiGate and FortiAnalyzer
The FortiGate must have IP reachability to the FortiAnalyzer to send logs over the network, typically using TCP port 514 (syslog) or FortiGate's proprietary log forwarding protocol. Without network connectivity, log transmission will fail regardless of configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable local logging on the FortiAnalyzer
Why it's wrong here
Enabling local logging on the FortiAnalyzer is incorrect because FortiAnalyzer is a centralized log collector, not a log source. Its local logging feature captures operational logs about FortiAnalyzer itself (e.g., system events, admin actions), not FortiGate traffic logs. To forward FortiGate logs to FortiAnalyzer, you must configure the FortiGate's remote logging settings, not toggle a local logging switch on the FortiAnalyzer.
- ✗
Create a firewall policy on the FortiGate to allow log traffic
Why it's wrong here
Creating a firewall policy specifically to allow log traffic is usually unnecessary because FortiAnalyzer communication uses the FortiGate's management or log forwarding channel, which is governed by the implicit administrative access rules, not standard firewall policies. In typical deployments, the FortiGate can reach the FortiAnalyzer over the management VDOM or via a dedicated logging interface without requiring a security policy. Only in a multi-VDOM or segmented environment might you need to ensure routing or policy-based routing, but a standard 'allow log' policy is not the primary prerequisite.
- ✓
Ensure network connectivity between FortiGate and FortiAnalyzer
Why this is correct
Ensuring network connectivity between the FortiGate and FortiAnalyzer is the essential prerequisite because the FortiGate must be able to reach the FortiAnalyzer's IP address on the correct port (e.g., HTTPS 443, SSH 22, or Syslog 514). Without IP reachability, proper routing, and administrative access enabled on the interface, log transmission cannot occur regardless of any other configuration. This step verifies the underlying transport path and is often the root cause when logs fail to appear on the FortiAnalyzer.
- ✗
Disable local logging on the FortiGate
Why it's wrong here
Disabling local logging on the FortiGate is counterproductive because local logging and remote logging to FortiAnalyzer are independent features. You can (and often should) keep local logging enabled for real-time monitoring and troubleshooting, even when also sending logs to FortiAnalyzer. Disabling local logging would not facilitate forwarding; it would only remove the ability to access logs directly on the FortiGate, while the FortiAnalyzer configuration remains unchanged.
- ✓
Configure the FortiGate to send logs to the FortiAnalyzer
Why this is correct
Configuring the FortiGate to send logs to the FortiAnalyzer is the core configuration step: under System > Log Settings, you must add a FortiAnalyzer log server, specify its IP address, set the protocol (typically HTTPS or SSH), and ensure the FortiAnalyzer device is registered and authorized. This setting tells the FortiGate exactly where to forward logs and how to authenticate. Without this explicit remote log server configuration, the FortiAnalyzer will never receive FortiGate logs, even with perfect network connectivity.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.