nerdexam
Fortinet

FCP_FAZ_AD-7.4 · Question #11

Refer to the exhibit. The capture displayed was taken on a FortiAnalyzer. Why is a single IP address shown as the source for all logs received?

The correct answer is C. FortiAnalyzer is receiving logs from the root FortiGate of a Security Fabric. In a Fortinet Security Fabric, logs from downstream devices can be sent to FortiAnalyzer through the root FortiGate. This is why all the logs have the same source IP address (the root FortiGate). The root FortiGate aggregates and forwards the logs from all downstream devices…

Logging and Archiving

Question

Refer to the exhibit. The capture displayed was taken on a FortiAnalyzer. Why is a single IP address shown as the source for all logs received?

Exhibit

FCP_FAZ_AD-7.4 question #11 exhibit

Options

  • AFortiAnalyzer is using the device MAC addresses to differentiate their logs.
  • BThe logs belong to devices that are part of a high availability (HA) cluster.
  • CFortiAnalyzer is receiving logs from the root FortiGate of a Security Fabric.
  • DThe device sending logs has two VDOMs in the same ADOM.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    83% (43)
  • D
    10% (5)

Explanation

In a Fortinet Security Fabric, logs from downstream devices can be sent to FortiAnalyzer through the root FortiGate. This is why all the logs have the same source IP address (the root FortiGate). The root FortiGate aggregates and forwards the logs from all downstream devices, so the source IP in the log capture will appear to be from the root FortiGate itself, even though the logs originate from multiple devices within the fabric.

Topics

#Security Fabric#log source IP#root FortiGate#log collection

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AD-7.4 Practice