Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

A company uses Active Directory for user authentication. They want users to automatically authenticate to the FortiGate without entering credentials when accessing the internet. Which authentication method should the administrator configure?

⚠ Common exam trap

A common mix-up: candidates confuse LDAP authentication (which requires credential entry) with FSSO (which provides transparent authentication), leading them to select LDAP with captive portal thinking it integrates with Active Directory for automatic login.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FSSO with Active Directory polling

FSSO (Fortinet Single Sign-On) with Active Directory polling allows users to be automatically authenticated to the FortiGate based on their existing Windows domain login. The FortiGate polls the domain controllers for user logon events, mapping the user's IP address to their authenticated identity without requiring any additional credential entry. This meets the requirement of transparent internet access authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LDAP authentication with captive portal

    Why it's wrong here

    LDAP authentication with captive portal is interactive, not transparent. When a user tries to browse the web, the FortiGate redirects them to a captive portal page where they must manually enter their AD username and password. FortiGate then performs an LDAP bind against Active Directory to validate those credentials. Because the user is forced to type credentials instead of being recognized automatically from their domain logon, this option does not provide the transparent authentication required.

  • ✗

    RADIUS authentication with PAP

    Why it's wrong here

    RADIUS authentication with PAP also requires the user to submit a username and password, typically through a login prompt or VPN client. With PAP, the password is sent in cleartext to the RADIUS server, and there is no polling of Active Directory logon events. The FortiGate merely forwards the credentials to a RADIUS server for validation, which means the user must actively authenticate each time. This is manual, not transparent, and therefore fails the requirement for seamless domain-user recognition.

  • ✗

    Local user authentication

    Why it's wrong here

    Local user authentication involves creating user accounts manually on the FortiGate, completely separate from Active Directory. Each user would have to type their credentials when accessing the network, and there is no automatic integration with domain logons or AD group memberships. Managing a separate local user database is inefficient and does not provide single sign-on. This option is wrong because it requires manual login and does not leverage the company's existing Active Directory infrastructure for transparent authentication.

  • ✓

    FSSO with Active Directory polling

    Why this is correct

    FSSO with Active Directory polling is correct because it provides transparent, non-interactive authentication. A collector agent polls the Active Directory domain controllers for Windows security event logs, capturing successful user logon events and mapping them to the user's IP address. This information is sent to the FortiGate, which dynamically associates the user's traffic with their AD identity without requiring any manual credential entry. As a result, the firewall can apply user-based policies based on AD logon activity, seamlessly authenticating users as they access the network.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.