exam questions

Exam FCP_FAZ_AD-7.4 All Questions

View all questions & answers for the FCP_FAZ_AD-7.4 exam

Exam FCP_FAZ_AD-7.4 topic 1 question 22 discussion

Actual exam question from Fortinet's FCP_FAZ_AD-7.4
Question #: 22
Topic #: 1
[All FCP_FAZ_AD-7.4 Questions]

In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?

  • A. The traffic destination is another FortiGate in the fabric.
  • B. The upstream FortiGate is configured to do NAT.
  • C. Log redundancy is configured in the fabric.
  • D. The downstream device cannot connect to FortiAnalyzer.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Slikings
1 month, 4 weeks ago
A. Incorrect, the only thing that changes the log it was received by is UTM and NAT logs B. Correct, UTM and NAT C. incorrect D. incorrect, all logs in the fabric appear as coming from the root FG A session's traffic logging is always done by the first FG that handled it in the Fabric. FG devices in the fabric know the MAC of their upstream and downstream peers. It does not generate a log for packets coming from other FG's to eliminate the repeated logging of a session. The exception is if the upstream FG performs NAT, this is needed to record details such as translated ports and addresses. UTM logs are another exception.
upvoted 4 times
...
066c9f3
2 months ago
Selected Answer: B
NATting needs to be performed, otherwise the session / log will count as one across all firewalls in the fabric. After NAT, a new log is generated.
upvoted 1 times
...
Beatledrew
3 months ago
Correct. B. Page 48 of the Study Guide
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago