Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

An administrator needs to monitor FortiGate session count and CPU usage over time using FortiAnalyzer. Which log type should be configured for this?

⚠ Common exam trap

Watch out — candidates often confuse 'traffic logs' with performance monitoring because traffic logs show session details, but they do not provide the aggregated, time-series CPU and session count data that performance logs uniquely offer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Performance logs

Performance logs are specifically designed to capture system resource utilization metrics such as CPU usage, memory consumption, and session counts over time. FortiAnalyzer uses these logs to generate historical performance graphs and reports, enabling administrators to monitor trends and identify resource bottlenecks. Security logs, event logs, and traffic logs do not contain the periodic, time-series resource data required for this monitoring purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security logs

    Why it's wrong here

    Security logs record traffic and threat events, not device health metrics, so session count and CPU usage never appear there. It is tempting because security logs are the default FortiAnalyzer feed, and they would be the correct choice when investigating intrusions or policy violations rather than performance monitoring.

  • ✓

    Performance logs

    Why this is correct

    Performance logs capture periodic system statistics such as session counts and CPU utilisation, which FortiAnalyzer stores for historical graphing and trend reporting. Other log types record traffic or events, not the time-series resource metrics the administrator needs.

  • ✗

    Event logs

    Why it's wrong here

    Event logs capture system and administrative activities, not the periodic performance statistics FortiAnalyzer graphs for session count and CPU usage. Event logging is tempting because it records device activity, and it would be correct for auditing configuration changes rather than resource monitoring.

  • ✗

    Traffic logs

    Why it's wrong here

    Traffic logs record individual sessions and their contents, not periodic device resource statistics such as session count and CPU usage. Traffic logging is tempting because it captures session data, and it would be correct for detailed traffic analysis rather than performance monitoring over time.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.