NSE4 · Question #516
What determines whether a log message is generated or not?
The correct answer is A. Firewall policy setting. The decision of whether a log message is generated for network traffic on a FortiGate is primarily determined by the logging settings within the firewall policies.
Question
What determines whether a log message is generated or not?
Options
- AFirewall policy setting
- BLog Settings in the GUI
- C'config log' command in the CLI
- DSyslog
- EWebtrends
How the community answered
(43 responses)- A93% (40)
- D5% (2)
- E2% (1)
Why each option
The decision of whether a log message is generated for network traffic on a FortiGate is primarily determined by the logging settings within the firewall policies.
Each firewall policy contains specific logging options (e.g., 'Log Allowed Traffic', 'Log Denied Traffic') that dictate whether sessions matching that policy will generate log messages upon completion or denial.
GUI Log Settings configure global log destinations (like FortiAnalyzer or local disk) and general logging preferences, but not the per-session decision to generate a log.
The 'config log' command in the CLI is used for configuring global logging settings and destinations, similar to the GUI Log Settings, rather than individual log generation decisions.
Syslog is a protocol and a destination for log messages, not the mechanism that determines if a log message is created by the FortiGate in the first place.
Webtrends is an external web analytics service and has no direct influence on whether a FortiGate generates log messages for its network traffic.
Concept tested: FortiGate firewall policy logging
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469904/firewall-policies
Topics
Community Discussion
No community discussion yet for this question.