Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator notices that traffic matching a firewall policy is not being logged. The policy has logging enabled. The FortiGate has local disk storage. What should the administrator check first?

⚠ Common exam trap

NSE4 often tests the assumption that logging issues are always about severity or remote destinations — candidates overlook that local disk health and free space are the first thing to verify when local logging silently stops.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The disk health and available space using 'diagnose sys disk' commands

When a FortiGate policy has logging enabled but logs are not appearing, and the device uses local disk storage, the first thing to check is whether the disk is healthy and has available space. FortiOS stops writing logs when the disk is full or failing, and 'diagnose sys disk' commands reveal disk health, usage, and log partition status. This is the most direct and common cause of missing local logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Whether the FortiGate has a valid FortiAnalyzer subscription

    Why it's wrong here

    FortiAnalyzer subscription is not a prerequisite for local disk logging because the FortiGate's built-in storage is always present and unlicensed. Local logs are written directly to the on-board disk or SSD without any FortiAnalyzer affiliation. If the disk is full or failing, logs will be lost regardless of subscription status. Therefore, checking a FortiAnalyzer subscription would not identify the root cause of missing local logs.

  • ✗

    Whether FortiCloud logging is enabled

    Why it's wrong here

    FortiCloud logging is a remote logging feature that sends events to the FortiCloud service, but it operates independently from the local disk log path. Enabling FortiCloud does not change how the FortiGate writes to its local hard drive, and disabling it does not stop local logging. Since the problem concerns missing logs on the local disk, checking FortiCloud status is irrelevant; the on-box logging pipeline has no dependency on the cloud service.

  • ✓

    The disk health and available space using 'diagnose sys disk' commands

    Why this is correct

    When local logs are missing, the first step is to verify the storage subsystem with 'diagnose sys disk' to inspect disk health, mount status, and available space. A full or failing disk, or an exhausted inode table, can cause log writes to fail silently, resulting in no entries in the local log view. This command reveals whether the disk is online, has sufficient free blocks, and has no file-system errors. Only after confirming the disk is healthy should you examine logging filters or remote destinations.

  • ✗

    The log severity level on the policy

    Why it's wrong here

    Log severity on a firewall policy controls the minimum event severity that will be recorded; for example, setting it to 'emergency' would suppress typical traffic logs at 'information' level. While an overly strict severity setting can reduce log volume, it would not produce a complete absence of logs if the policy also has logging enabled and disk space is available. Severity filtering happens after a log entry is generated, so a healthy disk with the correct enable-logging setting would still show some traffic. Thus, severity misconfiguration is a secondary suspect compared to disk-related failures.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to send logs to both a local disk and a remote FortiCloud account. Which two conditions must be met for this to work? (Choose two.)

easy
  • A.The FortiGate must be configured to log to both destinations simultaneously
  • ✓ B.The FortiGate must have a valid FortiCloud subscription
  • C.The FortiGate must be in NAT mode
  • ✓ D.The FortiGate must have a hard disk or SSD installed
  • E.The FortiGate must have a policy to allow outbound traffic to FortiCloud

Why B: The FortiGate must have local storage (disk) to store logs locally. It also must have connectivity to FortiCloud servers, and logging to FortiCloud must be enabled. The local disk logging is a separate configuration.

Variation 2. An administrator wants to ensure that log messages are categorized by severity and that only events with severity 'error' and above are sent to the syslog server. Which configuration should be used?

medium
  • A.Set 'set severity critical' in syslog config
  • ✓ B.Set 'set severity error' in syslog config
  • C.Set 'set severity warning' in syslog config
  • D.Set 'set severity alert' in syslog config

Why B: In FortiGate syslog configuration, the 'set severity' parameter defines the minimum severity level that will be forwarded; setting it to 'error' means error, critical, alert, and emergency messages are sent, while warning, notification, information, and debug are suppressed. This matches the requirement to send only 'error and above.' The severity levels follow the syslog RFC 5424 ordering, so choosing the correct threshold is a matter of knowing that ordering.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.