nerdexam
Fortinet

NSE4 · Question #246

Both the FortiGate and FortiAnalyzer units can notify administrators when certain alert conditions are met. Considering this, which of the following statements is NOT correct?

The correct answer is B. On a FortiAnalyzer device, the alert condition is based either on the severity level or on the log. The statement that FortiAnalyzer alert conditions are based solely on severity level or log type is incorrect, as FortiAnalyzer's alerting system relies on sophisticated event handlers and datasets for more complex conditions.

Submitted by rania.sa· Apr 18, 2026Logging and Monitoring

Question

Both the FortiGate and FortiAnalyzer units can notify administrators when certain alert conditions are met. Considering this, which of the following statements is NOT correct?

Options

  • AOn a FortiGate device, the alert condition is based either on the severity level or on the log type,
  • BOn a FortiAnalyzer device, the alert condition is based either on the severity level or on the log
  • COnly a FortiAnalyzer device can send the alert notification in the form of a syslog message.
  • DBoth the FortiGate and FortiAnalyzer devices can send alert notifications in the form of an email

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    91% (30)
  • D
    3% (1)

Why each option

The statement that FortiAnalyzer alert conditions are based solely on severity level or log type is incorrect, as FortiAnalyzer's alerting system relies on sophisticated event handlers and datasets for more complex conditions.

AOn a FortiGate device, the alert condition is based either on the severity level or on the log type,

FortiGate devices can configure alerts based on log severity levels (e.g., critical, error) or specific log types (e.g., traffic, event, virus), making this a correct statement.

BOn a FortiAnalyzer device, the alert condition is based either on the severity level or on the logCorrect

This statement is NOT correct because FortiAnalyzer's alerting system is significantly more advanced, utilizing Event Handlers that allow for complex conditions based on queries of log data, correlation of events, and thresholds, rather than being limited to simple severity or log type.

COnly a FortiAnalyzer device can send the alert notification in the form of a syslog message.

FortiGate devices can also send log messages and alerts to syslog servers, so stating that 'Only a FortiAnalyzer device can send the alert notification in the form of a syslog message' is incorrect.

DBoth the FortiGate and FortiAnalyzer devices can send alert notifications in the form of an email

Both FortiGate and FortiAnalyzer devices are capable of sending alert notifications in the form of an email, making this a correct statement.

Concept tested: FortiGate and FortiAnalyzer alert configuration differences

Source: https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/339414/event-handlers

Topics

#FortiGate alerts#FortiAnalyzer alerts#Logging#Monitoring

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice