Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

An administrator is investigating a security incident and needs to view raw logs from a FortiAnalyzer for a specific time range. The administrator wants to ensure the logs are not aggregated or summarized. Which type of log view should be used?

⚠ Common exam trap

Many exam-takers confuse FortiView's real-time graphical summaries with raw log access, assuming 'Log View' is just another dashboard, when in fact FortiView aggregates data and Log View shows the original unmodified logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log View

The Log View in FortiAnalyzer displays raw, unaggregated logs exactly as received from FortiGate devices, making it the correct choice for viewing logs without summarization. Unlike other views that pre-process or summarize data, Log View provides direct access to the original log entries for a specified time range, which is essential for detailed incident investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event Management

    Why it's wrong here

    Event Management handles alerting, incident correlation and handlers built on log data; its views are filtered and grouped rather than raw. It fits monitoring and response workflows. Viewing unaggregated individual log entries for a specific time range requires Log View.

  • ✗

    FortiView

    Why it's wrong here

    FortiView presents aggregated, summarised dashboards and drill-down charts, so entries are consolidated rather than raw. It suits traffic trending and top-N analysis. The scenario demands unsummarised individual log entries for a time range, which Log View provides instead.

  • ✗

    Reports

    Why it's wrong here

    Reports generate scheduled or on-demand formatted summaries, charts and statistics, so data is aggregated by design. They suit compliance evidence and management reporting. The scenario needs unsummarised raw entries for a time range, which Log View delivers.

  • ✓

    Log View

    Why this is correct

    Log View presents raw, unaggregated log entries for the selected time range, preserving each individual event. Other views roll records into summaries or charts, which would hide the granular detail the administrator needs during incident investigation.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.