Courseiva

NSE4 Firewall Policies and NAT Practice Question

You execute 'get firewall policy 5' and see the following output: policyid=5 name="test" status=enable schedule="always" logtraffic=all What does 'logtraffic=all' mean?

⚠ Common exam trap

Many candidates confuse 'logtraffic=all' with 'logtraffic=session-start' or think it only logs denied traffic, but FortiGate's granular log options require precise understanding of each keyword's behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All traffic matching the policy will be logged, regardless of action

'logtraffic=all' in FortiGate firewall policy configuration means that every packet belonging to a session matching this policy will be logged, regardless of whether the action is accept or deny. This is distinct from other log settings like 'logtraffic=utm' or 'logtraffic=disable', and it ensures full audit trail for all traffic handled by the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only the first packet of each session will be logged

    Why it's wrong here

    The 'logtraffic' parameter in FortiOS policy configuration does not support a mode that records only the initial packet of a session. Instead, FortiOS logs session-based events, meaning each session is logged at establishment and termination, or according to the selected log mode. A 'first packet only' behavior would effectively be a custom logging or sampling feature, not what 'logtraffic=all' designates. Therefore, this option mischaracterizes the 'all' setting.

  • ✗

    Only traffic that triggers a security profile will be logged

    Why it's wrong here

    When 'logtraffic=utm' is configured, only sessions that are evaluated by UTM security profiles and produce log entries from those profiles are recorded. In contrast, 'logtraffic=all' captures every session that matches the policy, irrespective of whether any security profile triggers. Since 'all' does not condition logging on UTM profile events, this answer incorrectly narrows the scope. Thus, the notion that only security-profile-triggering traffic is logged applies to 'utm', not 'all'.

  • ✗

    Only traffic that is denied by the policy will be logged

    Why it's wrong here

    Logging with 'logtraffic=all' applies to both permitted and denied sessions, so it is not limited to traffic denied by the policy. If you wanted to log only denied sessions while excluding allowed ones, you would typically configure action 'deny' with logtraffic enabled or use a specific log setting, but that is not what 'all' means. The 'all' setting ensures that any session matching the policy—whether accepted or blocked—generates a log entry. Hence, this option incorrectly restricts logging to just denied traffic.

  • ✓

    All traffic matching the policy will be logged, regardless of action

    Why this is correct

    The 'all' setting for the 'logtraffic' option on a Fortinet firewall policy instructs the device to log every session that matches the policy, regardless of the action taken (accept or deny). This includes sessions that are allowed through as well as those that are explicitly blocked. It is the most comprehensive logging mode for a policy and is often used for audit compliance or troubleshooting. Therefore, this option correctly describes the behavior of 'logtraffic=all'.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.