FCP_FAZ_AN-7.6 · Question #13
Refer to the exhibit. Client-1 is trying to access the internet for web browsing. All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All…
The correct answer is A. Both FGT-A and FGT-B will create traffic logs. Each FortiGate independently logs all sessions that pass through it when logging is enabled on its policies. In this topology, both FGT-B (where Client-1's traffic first enters) and FGT-A (which forwards the traffic to the internet) see and log the session, so both devices…
Question
Refer to the exhibit. Client-1 is trying to access the internet for web browsing. All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations. Which statement about the logging behavior for this specific traffic flow is true?
Exhibit
Options
- ABoth FGT-A and FGT-B will create traffic logs.
- BFGT-A will see the MAC address of FGT-B in the packets and know it does not need to log this
- CFGT-A will create logs for web filter events only if FGT-B did not already detect a violation.
- DFGT-A will create all traffic logs except for security logs.
How the community answered
(27 responses)- A85% (23)
- B4% (1)
- C4% (1)
- D7% (2)
Explanation
Each FortiGate independently logs all sessions that pass through it when logging is enabled on its policies. In this topology, both FGT-B (where Client-1's traffic first enters) and FGT-A (which forwards the traffic to the internet) see and log the session, so both devices generate traffic logs for this web-browsing flow.
Topics
Community Discussion
No community discussion yet for this question.
