NSE7 Enterprise Firewall and VDOMs Practice Question
A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?
⚠ Common exam trap
Many exam-takers confuse FortiAnalyzer's ADOM feature (which is for administrative separation) with log collection or reporting, or they mistakenly associate automation stitches or policy packages with compliance reporting, which are actually features of FortiGate or FortiManager, not FortiAnalyzer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log analytics
Log analytics (option B) is correct because it provides the ability to search, filter, and visualize logs from multiple FortiGates, enabling the identification of trends and anomalies necessary for compliance reporting. Reports (option C) is correct because FortiAnalyzer includes a dedicated reporting engine that can generate scheduled or on-demand compliance reports based on collected logs, with pre-defined templates for standards like PCI DSS, HIPAA, and SOX.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ADOM configuration
Why it's wrong here
ADOM configuration partitions administrative domains and devices for management separation, but it does not itself collect logs or generate compliance reports. It is tempting because ADOMs organise multiple FortiGates, yet the features required are device log registration and report templates that produce the compliance output.
- ✓
Log analytics
Why this is correct
Log analytics aggregates and correlates log data from multiple FortiGates, letting the engineer build compliance reports from consolidated views. It satisfies the multi-device collection and reporting requirement directly, rather than relying on per-device raw logs.
- ✓
Reports
Why this is correct
Reports satisfy the compliance-reporting requirement by aggregating the logs FortiGates forward to FortiAnalyzer, then rendering scheduled or on-demand output from report templates and datasets. Log collection itself is handled by the logging and log-forwarding features, so Reports supplies the reporting half of this scenario's two-part need.
- ✗
Automation stitches
Why it's wrong here
Automation stitches trigger automated responses to events, such as quarantining or running scripts, rather than collecting logs or producing compliance reports. It is tempting because automation supports operational workflows, but the required features are log collection via device registration and report generation through report templates.
- ✗
Policy packages
Why it's wrong here
Policy packages in FortiAnalyzer are containers for provisioning security policies to managed FortiGates, not mechanisms for log collection or compliance reporting. It is tempting because policy management sounds central to compliance, yet the scenario needs log receipt from registered devices and report templates for the reports.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.