Courseiva
Enterprise Firewall and VDOMsmediumMultiple ChoiceObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator is troubleshooting a scenario where FortiAnalyzer is not receiving logs from a FortiGate. The FortiGate shows 'log-fortianalyzer setting status: disconnected'. Which step should be taken first to resolve this?

⚠ Common exam trap

The trap here is that candidates often jump to reconfiguring logging or restarting services (options C or D) without first verifying the most fundamental Layer 3 connectivity and service availability, which is the logical starting point for any 'disconnected' status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that the FortiGate can reach the FortiAnalyzer IP address and that the FortiAnalyzer service is running

The 'disconnected' status indicates that the FortiGate cannot establish a TCP connection to the FortiAnalyzer. The first step is to verify basic Layer 3 reachability (ping) and that the FortiAnalyzer service is listening on the default port (TCP 514 or 3000 for encrypted). Without confirming these, further troubleshooting is premature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Check the FortiGate's DNS resolution for the FortiAnalyzer hostname

    Why it's wrong here

    DNS is only relevant if using hostname; the status shows disconnected, likely IP-based.

  • Verify that the FortiGate can reach the FortiAnalyzer IP address and that the FortiAnalyzer service is running

    Why this is correct

    Connectivity is the most basic check; ping and service status should be verified first.

  • Restart the FortiGate's logging service

    Why it's wrong here

    Restarting may not resolve underlying connectivity.

  • Disable and re-enable logging to FortiAnalyzer

    Why it's wrong here

    Toggling may help but should be done after connectivity is confirmed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.