Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator needs to send logs from a FortiGate to a remote FortiAnalyzer for centralized log storage and analysis. Which configuration step is required on the FortiGate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the FortiAnalyzer as the log destination in Log Settings

To send logs to FortiAnalyzer, the administrator must configure the FortiAnalyzer as a remote log destination under Log Settings. This is done via 'config log fortianalyzer setting' and specifying the server IP and other parameters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a firewall policy allowing traffic from FortiGate to FortiAnalyzer on port 514

    Why it's wrong here

    Port 514 is syslog; FortiAnalyzer uses port 514 (or 3000) by default, but the primary step is configuring the FortiAnalyzer server address, not just a policy. A policy is needed if traffic is blocked, but the configuration is the essential step.

  • ✓

    Set the FortiAnalyzer as the log destination in Log Settings

    Why this is correct

    Set the FortiAnalyzer as the log destination in Log Settings. Under System > Log Settings (or via CLI 'config log fortianalyzer setting'), the administrator must specify the FortiAnalyzer IP address and enable log transmission. This action directs the FortiGate to send logs using the native FortiAnalyzer protocol, which provides reliable, acknowledged log delivery. Without this configuration, logs will never leave the FortiGate, regardless of any firewall policies or forwarding rules.

  • ✗

    Create a log forwarding rule to forward all logs to the FortiAnalyzer

    Why it's wrong here

    Create a log forwarding rule to forward all logs to the FortiAnalyzer. This is incorrect because FortiGate log forwarding is intended for sending logs to external syslog servers, not for integrating with FortiAnalyzer. FortiAnalyzer communication uses the proprietary FortiAnalyzer protocol (or port 514/3000 with handshake and serial number validation), not a generic log forwarding rule. Even if the FortiAnalyzer could accept syslog, it would lack the native features such as device authorization, event correlation, and structured log parsing that the dedicated FortiAnalyzer setting provides.

  • ✗

    Install a FortiGate connector on the FortiAnalyzer

    Why it's wrong here

    Install a FortiGate connector on the FortiAnalyzer. There is no 'FortiGate connector' to install; FortiAnalyzer manages FortiGates through its own Device Manager by adding the FortiGate's serial number and accepting its connection. The required configuration is entirely on the FortiGate side—setting the FortiAnalyzer as the log destination. Placing the action on the FortiAnalyzer confuses the device roles and introduces terminology that does not exist in Fortinet's management architecture.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.