nerdexam
Fortinet

FCP_FAZ_AN-7.4 · Question #13

Refer to the exhibit. Client-1 is trying to access the internet for web browsing. All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All…

The correct answer is A. Both FGT-A and FGT-B will create traffic logs. FGT-B will create log for initial session - FGT-B will create log as a resultat of SNAT

Logging and Archiving

Question

Refer to the exhibit. Client-1 is trying to access the internet for web browsing. All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations. Which statement about the logging behavior for this specific traffic flow is true?

Exhibit

FCP_FAZ_AN-7.4 question #13 exhibit

Options

  • ABoth FGT-A and FGT-B will create traffic logs.
  • BFGT-A will see the MAC address of FGT-B in the packets and know it does not need to log this
  • CFGT-A will create logs for web filter events only if FGT-B did not already detect a violation.
  • DOnly FGT-A will create traffic logs.

How the community answered

(35 responses)
  • A
    83% (29)
  • B
    11% (4)
  • C
    3% (1)
  • D
    3% (1)

Explanation

  • FGT-B will create log for initial session - FGT-B will create log as a resultat of SNAT

Topics

#Security Fabric logging#traffic logs#FortiGate topology#log behavior

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AN-7.4 Practice