exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 55 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 55
Topic #: 1
[All NSE7_EFW-7.2 Questions]

Which FortiGate in a Security Fabric sends logs to FortiAnalyzer?

  • A. Only the root FortiGate.
  • B. Each FortiGate in the Security Fabric.
  • C. The FortiGate devices performing network address translation (NAT) or unified threat management (UTM), if configured.
  • D. Only the last FortiGate that handled a session in the Security Fabric.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
myrmidon3
4 months, 2 weeks ago
Selected Answer: B
In a Security Fabric, every FortiGate device sends its logs directly to FortiAnalyzer, independently of the root FortiGate. While the root FortiGate is typically responsible for configuring and managing the log forwarding configuration, all leaf FortiGates (downstream devices) send their logs to FortiAnalyzer, ensuring complete visibility across the Security Fabric. This design ensures redundancy and guarantees that logs are not lost if a specific FortiGate device in the fabric fails. Other options are incorrect for the following reasons: A: Only the root FortiGate is responsible for configuration synchronization, not exclusive logging. C: NAT or UTM devices log traffic details, but all devices in the Security Fabric send logs, not just these. D: Logging is not limited to the last FortiGate in the session chain; all devices log their activity independently.
upvoted 1 times
...
Febrian
5 months, 2 weeks ago
Selected Answer: B
All Fortigates send logs to FortiAnalyzer. But session logs only sent by first fortigate that handle the session, so it's not being duplicated. If any fortigate that performs NAT or UTM, it will generate additional log for that session and send it to FortiAnalyzer. See page 69
upvoted 1 times
...
Totoahren
5 months, 3 weeks ago
Selected Answer: B
Study Guide 7.2 Page 68 - see the last comment.
upvoted 2 times
...
140ecf2
7 months ago
Selected Answer: C
C is correct. see on P.68. Doesn't create duplicate except NAT and UTM traffic
upvoted 1 times
...
Mellon
8 months, 2 weeks ago
Selected Answer: C
Study guide P.69
upvoted 1 times
...
Mellon
8 months, 2 weeks ago
The correct answer is "The first FGT that handles a session". Study guide p.68
upvoted 1 times
...
charruco
11 months, 2 weeks ago
Selected Answer: B
B is correct Study Guide 7.2 Page 64
upvoted 2 times
...
GCISystemIntegrator
12 months ago
Selected Answer: B
p.64 study guide
upvoted 1 times
...
dsticht
1 year ago
Selected Answer: B
A is wrong, because only Root applies specifically to topology information, not logs. ALL devices send logs.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...