NSE4 System and Network Administration Practice Question
An administrator needs to forward logs from a FortiGate to a FortiAnalyzer for centralized logging. The FortiAnalyzer IP is 10.10.10.10. Which configuration is required on the FortiGate?
⚠ Common exam trap
Test-takers frequently confuse the `config log fortianalyzer setting` command with the `config system central-management` command (used for FortiManager) or the syslog configuration, leading them to select options that configure the wrong service or miss the required `set status enable` step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
config log fortianalyzer setting set status enable set server 10.10.10.10 end
The FortiGate uses the `config log fortianalyzer setting` command to configure direct logging to a FortiAnalyzer. This command enables the log forwarding feature (`set status enable`) and specifies the FortiAnalyzer's IP address (`set server 10.10.10.10`). The other options either use incorrect command paths or are intended for different logging destinations (e.g., syslog or central management).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
config system central-management set type fortianalyzer set ip 10.10.10.10 end
Why it's wrong here
This CLI path belongs to the system central-management engine, which establishes the outbound management tunnel to FortiManager, not a log collector. The type option under config system central-management does not accept 'fortianalyzer', and FortiAnalyzer log forwarding is configured under the log hierarchy, not as a management-enterprise connection. Even hypothetically, this would not create a log-upload channel to a FortiAnalyzer device.
- ✗
config log setting set fortianalyzer ip 10.10.10.10 end
Why it's wrong here
Under config log setting you configure global logging behaviors such as local log retention, log rotation, and per-device log settings, not a FortiAnalyzer connector. The subcommand 'set fortianalyzer ip' does not exist in this branch, so the CLI would reject it. FortiAnalyzer integration has its own dedicated settings tree under config log fortianalyzer setting, with separate commands for enabling the status and specifying the server address.
- ✗
config log syslogd setting set server 10.10.10.10 end
Why it's wrong here
The config log syslogd setting block is used to stream log messages to third-party syslog servers over UDP/TCP, typically on port 514, not to send them to a FortiAnalyzer appliance. A syslog destination lacks FortiAnalyzer-specific capabilities such as event correlation, reporting, and log indexing, and FortiAnalyzer does not accept native FortiGate log data through a generic syslog listener by default. This command is valid for syslog but does not fulfill the requirement to forward logs to a FortiAnalyzer.
- ✓
config log fortianalyzer setting set status enable set server 10.10.10.10 end
Why this is correct
This is the correct FortiOS CLI branch for enabling FortiAnalyzer log forwarding. 'set status enable' activates the FortiAnalyzer connection, and 'set server 10.10.10.10' defines the destination FortiAnalyzer appliance's IP address; optional settings like 'set upload enable' control exactly how logs are pushed. Once committed, the FortiGate establishes a dedicated logging channel to FortiAnalyzer, which is the intended method for collecting logs on that platform.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.