NSE4 · Question #246
Both the FortiGate and FortiAnalyzer units can notify administrators when certain alert conditions are met. Considering this, which of the following statements is NOT correct?
The correct answer is B. On a FortiAnalyzer device, the alert condition is based either on the severity level or on the log. The statement that FortiAnalyzer alert conditions are based solely on severity level or log type is incorrect, as FortiAnalyzer's alerting system relies on sophisticated event handlers and datasets for more complex conditions.
Question
Both the FortiGate and FortiAnalyzer units can notify administrators when certain alert conditions are met. Considering this, which of the following statements is NOT correct?
Options
- AOn a FortiGate device, the alert condition is based either on the severity level or on the log type,
- BOn a FortiAnalyzer device, the alert condition is based either on the severity level or on the log
- COnly a FortiAnalyzer device can send the alert notification in the form of a syslog message.
- DBoth the FortiGate and FortiAnalyzer devices can send alert notifications in the form of an email
How the community answered
(33 responses)- A6% (2)
- B91% (30)
- D3% (1)
Why each option
The statement that FortiAnalyzer alert conditions are based solely on severity level or log type is incorrect, as FortiAnalyzer's alerting system relies on sophisticated event handlers and datasets for more complex conditions.
FortiGate devices can configure alerts based on log severity levels (e.g., critical, error) or specific log types (e.g., traffic, event, virus), making this a correct statement.
This statement is NOT correct because FortiAnalyzer's alerting system is significantly more advanced, utilizing Event Handlers that allow for complex conditions based on queries of log data, correlation of events, and thresholds, rather than being limited to simple severity or log type.
FortiGate devices can also send log messages and alerts to syslog servers, so stating that 'Only a FortiAnalyzer device can send the alert notification in the form of a syslog message' is incorrect.
Both FortiGate and FortiAnalyzer devices are capable of sending alert notifications in the form of an email, making this a correct statement.
Concept tested: FortiGate and FortiAnalyzer alert configuration differences
Source: https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/339414/event-handlers
Topics
Community Discussion
No community discussion yet for this question.