nerdexam
Fortinet

FCSS_SASE_AD-24 · Question #38

When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost empty report?

The correct answer is B. Log allowed traffic is set to Security Events for all policies. If "Log allowed traffic" is set only to "Security Events" for all policies, only specific security events (such as blocked or malicious traffic) are logged, while general allowed traffic is not recorded. This results in a daily summary report with minimal data, as it lacks logs…

Monitoring and Reporting

Question

When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost empty report?

Options

  • ADigital experience monitoring is not configured.
  • BLog allowed traffic is set to Security Events for all policies.
  • CThe web filter security profile is not set to Monitor
  • DThere are no security profile group applied to all policies.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    83% (24)
  • C
    10% (3)
  • D
    3% (1)

Explanation

If "Log allowed traffic" is set only to "Security Events" for all policies, only specific security events (such as blocked or malicious traffic) are logged, while general allowed traffic is not recorded. This results in a daily summary report with minimal data, as it lacks logs of most regular traffic. To capture more detailed information, "Log allowed traffic" should be configured to record all traffic types, not just security events.

Topics

#traffic logging#security events logging#report data#FortiSASE reporting

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-24 Practice