Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator wants to send logs from a FortiGate to an external syslog server. Which log forwarding method should they configure?

⚠ Common exam trap

NSE4 often tests the confusion between log forwarding methods and monitoring protocols, so candidates might mistakenly choose SNMP or NetFlow because they are also used for network management, but only syslog is designed for sending detailed logs to an external server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syslog

FortiGate supports external log forwarding via syslog, which is the standard protocol for sending event and traffic logs to a remote server. Configuring syslog on the FortiGate involves specifying the server IP, port (default 514), and facility, and it allows the FortiGate to send logs in a structured format that can be parsed by SIEM or log management tools. SMTP is for email alerts, NetFlow is for traffic flow metadata, and SNMP is for monitoring and traps, not for general log transport.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Syslog

    Why this is correct

    Syslog is the standard protocol for forwarding system logs from network devices to a centralized log collector. FortiGate supports sending syslog messages to external servers over UDP (default 514), TCP, or TLS, with configurable severity and formats like RFC 3164 or RFC 5424. This makes it the correct choice for delivering FortiGate's full event logs to an external system.

  • ✗

    SMTP

    Why it's wrong here

    SMTP (Simple Mail Transfer Protocol) is designed solely for sending email messages, not for continuous or bulk log transfer. While FortiGate can send notification emails containing log excerpts or alerts, SMTP lacks the throughput, reliability, and structured message handling needed to transport the complete log stream to a logging server. Thus, it is unsuitable as a log forwarding protocol.

  • ✗

    NetFlow

    Why it's wrong here

    NetFlow is a protocol for collecting IP traffic flow metadata, such as source/destination addresses, ports, packet counts, and timestamps, primarily used for traffic analysis and anomaly detection. It does not convey event logs or security logs that include details like policy names, virus detection results, or content filtering actions. Even though some FortiGate models can export NetFlow, this is not a log forwarding mechanism.

  • ✗

    SNMP

    Why it's wrong here

    SNMP (Simple Network Management Protocol) is used for network device management and monitoring, allowing managers to read device statistics and receive traps for specific predefined conditions. It is not intended for transferring comprehensive log records; SNMP messages have small payloads and are structured around object identifiers (OIDs), not event text. Therefore, SNMP cannot replace syslog for forwarding FortiGate logs.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.