Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?

⚠ Common exam trap

Many exam-takers confuse FortiAnalyzer's ADOM feature (which is for administrative separation) with log collection or reporting, or they mistakenly associate automation stitches or policy packages with compliance reporting, which are actually features of FortiGate or FortiManager, not FortiAnalyzer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log analytics

Log analytics (option B) is correct because it provides the ability to search, filter, and visualize logs from multiple FortiGates, enabling the identification of trends and anomalies necessary for compliance reporting. Reports (option C) is correct because FortiAnalyzer includes a dedicated reporting engine that can generate scheduled or on-demand compliance reports based on collected logs, with pre-defined templates for standards like PCI DSS, HIPAA, and SOX.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ADOM configuration

    Why it's wrong here

    ADOM configuration partitions administrative domains and devices for management separation, but it does not itself collect logs or generate compliance reports. It is tempting because ADOMs organise multiple FortiGates, yet the features required are device log registration and report templates that produce the compliance output.

  • ✓

    Log analytics

    Why this is correct

    Log analytics aggregates and correlates log data from multiple FortiGates, letting the engineer build compliance reports from consolidated views. It satisfies the multi-device collection and reporting requirement directly, rather than relying on per-device raw logs.

  • ✓

    Reports

    Why this is correct

    Reports satisfy the compliance-reporting requirement by aggregating the logs FortiGates forward to FortiAnalyzer, then rendering scheduled or on-demand output from report templates and datasets. Log collection itself is handled by the logging and log-forwarding features, so Reports supplies the reporting half of this scenario's two-part need.

  • ✗

    Automation stitches

    Why it's wrong here

    Automation stitches trigger automated responses to events, such as quarantining or running scripts, rather than collecting logs or producing compliance reports. It is tempting because automation supports operational workflows, but the required features are log collection via device registration and report generation through report templates.

  • ✗

    Policy packages

    Why it's wrong here

    Policy packages in FortiAnalyzer are containers for provisioning security policies to managed FortiGates, not mechanisms for log collection or compliance reporting. It is tempting because policy management sounds central to compliance, yet the scenario needs log receipt from registered devices and report templates for the reports.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.