NSE7 Troubleshooting and Diagnostics Practice Question
An administrator is investigating a security incident and needs to view raw logs from a FortiAnalyzer for a specific time range. The administrator wants to ensure the logs are not aggregated or summarized. Which type of log view should be used?
⚠ Common exam trap
Many exam-takers confuse FortiView's real-time graphical summaries with raw log access, assuming 'Log View' is just another dashboard, when in fact FortiView aggregates data and Log View shows the original unmodified logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log View
The Log View in FortiAnalyzer displays raw, unaggregated logs exactly as received from FortiGate devices, making it the correct choice for viewing logs without summarization. Unlike other views that pre-process or summarize data, Log View provides direct access to the original log entries for a specified time range, which is essential for detailed incident investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event Management
Why it's wrong here
Event Management handles alerting, incident correlation and handlers built on log data; its views are filtered and grouped rather than raw. It fits monitoring and response workflows. Viewing unaggregated individual log entries for a specific time range requires Log View.
- ✗
FortiView
Why it's wrong here
FortiView presents aggregated, summarised dashboards and drill-down charts, so entries are consolidated rather than raw. It suits traffic trending and top-N analysis. The scenario demands unsummarised individual log entries for a time range, which Log View provides instead.
- ✗
Reports
Why it's wrong here
Reports generate scheduled or on-demand formatted summaries, charts and statistics, so data is aggregated by design. They suit compliance evidence and management reporting. The scenario needs unsummarised raw entries for a time range, which Log View delivers.
- ✓
Log View
Why this is correct
Log View presents raw, unaggregated log entries for the selected time range, preserving each individual event. Other views roll records into summaries or charts, which would hide the granular detail the administrator needs during incident investigation.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.