nerdexam
Fortinet

NSE4 · Question #308

An administrator needs to offload logging to FortiAnalyzer from a FortiGate with an internal hard drive. Which statements are true? (Choose two.)

The correct answer is A. Logs must be stored on FortiGate first, before transmitting to FortiAnalyzer D. FortiGate can encrypt communications using SSL encrypted OFTP traffic. When offloading logs to FortiAnalyzer from a FortiGate with local storage, logs are buffered locally before transmission, and communication can be secured using SSL-encrypted OFTP.

Submitted by ngozi_ng· Apr 18, 2026Logging and Monitoring

Question

An administrator needs to offload logging to FortiAnalyzer from a FortiGate with an internal hard drive. Which statements are true? (Choose two.)

Options

  • ALogs must be stored on FortiGate first, before transmitting to FortiAnalyzer
  • BFortiGate uses port 8080 for log transmission
  • CLog messages are transmitted as plain text in LZ4 compressed format (store-and-upload
  • DFortiGate can encrypt communications using SSL encrypted OFTP traffic.

How the community answered

(62 responses)
  • A
    89% (55)
  • B
    6% (4)
  • C
    5% (3)

Why each option

When offloading logs to FortiAnalyzer from a FortiGate with local storage, logs are buffered locally before transmission, and communication can be secured using SSL-encrypted OFTP.

ALogs must be stored on FortiGate first, before transmitting to FortiAnalyzerCorrect

FortiGate devices with local storage typically buffer or store logs internally before transmitting them to a FortiAnalyzer, ensuring log persistence and reliable delivery even if the FortiAnalyzer is temporarily unavailable.

BFortiGate uses port 8080 for log transmission

FortiGate typically uses TCP port 514 for OFTP (Fortinet proprietary log transfer protocol) to FortiAnalyzer, not port 8080.

CLog messages are transmitted as plain text in LZ4 compressed format (store-and-upload

While logs can be compressed and transmitted in a store-and-upload manner, log messages sent via OFTP can be encrypted, so they are not necessarily transmitted as plain text.

DFortiGate can encrypt communications using SSL encrypted OFTP traffic.Correct

FortiGate can secure its log transmission to FortiAnalyzer by encapsulating the Fortinet proprietary log transfer protocol (OFTP) within an SSL/TLS encrypted connection.

Concept tested: FortiGate to FortiAnalyzer log transmission

Source: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/204289/logging-and-archiving

Topics

#FortiGate Logging#FortiAnalyzer Integration#Log Transmission Protocol#Log Encryption

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice