Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_SSE_AD-7.6 Exam - Topic 3 Question 1 Discussion

An existing Fortinet SD-WAN customer who has recently deployed FortiSASE wants to have a comprehensive view of, and combined reports for, both SD-WAN branches and remote users. How can the customer achieve this?
C) Forward the logs from FortiSASE to the external FortiAnalyzer.
A) Forward the logs from FortiSASE to Fortinet SOCaaS.
B) Forward the logs from FortiGate to FortiSASE.
D) Forward the logs from the external SD-WAN FortiAnalyzer to FortiSASE.

Fortinet NSE5_SSE_AD-7.6 Exam - Topic 3 Question 1 Discussion

Actual exam question for Fortinet's NSE5_SSE_AD-7.6 exam
Question #: 1
Topic #: 3
[All NSE5_SSE_AD-7.6 Questions]

An existing Fortinet SD-WAN customer who has recently deployed FortiSASE wants to have a comprehensive view of, and combined reports for, both SD-WAN branches and remote users. How can the customer achieve this?

Show Suggested Answer Hide Answer
Suggested Answer: C

For customers with hybrid environments (on-premises SD-WAN branches and remote FortiSASE users), the FortiOS 7.6 and FortiSASE curriculum recommends centralized log aggregation for unified visibility.

Centralized Reporting: The standard architectural best practice is to forward logs from FortiSASE to an external FortiAnalyzer (Option C).

Unified View: Since the customer's on-premises FortiGate SD-WAN branches are already sending logs to an existing FortiAnalyzer, adding the FortiSASE log stream to that same FortiAnalyzer allows for the creation of combined reports.

Fabric Integration: This setup leverages the Security Fabric, enabling the FortiAnalyzer to provide a single pane of glass for monitoring security events, application usage, and SD-WAN performance metrics across the entire distributed network.

Why other options are incorrect:

Option A: SOCaaS is a managed service for threat monitoring, not a primary tool for an administrator to generate combined SD-WAN/SASE operational reports.

Option B: FortiSASE is not designed to act as a log collector or reporting hub for external on-premises FortiGates.

Option D: Data flows from the source (FortiSASE) to the collector (FortiAnalyzer), not the other way around.


Contribute your Thoughts:

0/2000 characters
Ellsworth
9 hours ago
Option B seems less effective. Why forward logs to FortiSASE?
upvoted 0 times
...
Tish
6 days ago
I'm leaning towards D. It seems logical to use the existing FortiAnalyzer.
upvoted 0 times
...
Juan
11 days ago
I agree, but option A could also work. SOCaaS might provide good insights.
upvoted 0 times
...
Frankie
16 days ago
I think option C is the best choice. FortiAnalyzer can consolidate logs effectively.
upvoted 0 times
...
Samira
2 months ago
I’ve heard good things about SOCaaS too, but not sure it fits here.
upvoted 0 times
...
Naomi
2 months ago
Just forward everything to FortiAnalyzer, makes sense!
upvoted 0 times
...
Krystal
2 months ago
Wait, can you really combine those logs effectively?
upvoted 0 times
...
Barney
3 months ago
I disagree, D seems more straightforward.
upvoted 0 times
...
Francesco
3 months ago
I think option C is the way to go!
upvoted 0 times
...
Golda
3 months ago
I'm going with option C. Keeps everything in the Fortinet ecosystem, which is probably the most straightforward solution.
upvoted 0 times
...
Laura
3 months ago
Option A seems like the way to go. Sending the FortiSASE logs to Fortinet SOCaaS should provide the combined reporting the customer needs.
upvoted 0 times
...
Antonio
3 months ago
Haha, option D is just silly. Forwarding logs from the SD-WAN FortiAnalyzer to FortiSASE? That's like putting the cart before the horse!
upvoted 0 times
...
Bobbye
3 months ago
I'm not sure about option B. Forwarding logs from FortiGate to FortiSASE doesn't seem like the right approach here.
upvoted 0 times
...
France
4 months ago
Option C looks good to me. Forwarding the logs from FortiSASE to the external FortiAnalyzer should give the customer a comprehensive view.
upvoted 0 times
...
Johana
4 months ago
I vaguely recall something about SOCaaS, but I'm not confident if that applies to getting combined reports for both branches and remote users.
upvoted 0 times
...
Teddy
4 months ago
I'm leaning towards option C, but I feel like I need to double-check if forwarding logs from FortiGate to FortiSASE is actually necessary.
upvoted 0 times
...
Amber
5 months ago
I remember a practice question where we had to consider log forwarding between FortiGate and FortiSASE. Could that be relevant here?
upvoted 0 times
...
Reid
5 months ago
I think forwarding logs from FortiSASE to FortiAnalyzer makes sense for a comprehensive view, but I'm not entirely sure if that's the best option.
upvoted 0 times
...
Launa
5 months ago
I'm not sure about this one. I'll need to carefully read through the options and think about how the Fortinet products work together.
upvoted 0 times
...
Ciara
5 months ago
This is straightforward, I've seen this type of integration question before. I'm confident I can identify the right approach.
upvoted 0 times
...
Alona
5 months ago
Okay, I think I've got a strategy here. I'll need to focus on how the logs can be shared between the different Fortinet products to get that comprehensive view.
upvoted 0 times
...
Viva
6 months ago
Hmm, I'm a bit confused on the relationship between FortiSASE and the SD-WAN components. I'll need to review my notes on integrating these solutions.
upvoted 0 times
...
Ardella
6 months ago
This seems like a tricky one. I'll need to think through the different options carefully.
upvoted 0 times
...

Save Cancel