NSE 4 – FortiGate 7.2 — Question 72

You have enabled logging on a FortiGate device for event logs and all security logs, and you have set up logging to use the FortiGate local disk.

What is the default behavior when the local disk is full?

Answer options

Correct answer: C

Explanation

The correct answer is C because when the local disk is full, FortiGate will start overwriting older logs after issuing a warning at the 75% usage threshold. Options A and B are incorrect as they do not reflect the overwrite behavior of the logging system, and D is incorrect because it states that the only warning occurs at 95%, which is not the case.