Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

A FortiGate admin has configured FSSO (Fortinet Single Sign-On) using Active Directory polling. Users authenticate to the domain but when accessing the internet through the FortiGate, they are still prompted for credentials. What is the MOST likely cause?

⚠ Common exam trap

Test-takers frequently assume the FortiGate must be domain-joined (Option D) or that the policy is misconfigured (Option C), when the real issue is the lack of polling to collect user logon events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate is not polling the AD domain controllers

In FSSO with Active Directory polling, the FortiGate must be configured to poll the domain controllers to retrieve user logon events. If polling is not set up or fails, the FortiGate will not have the user-to-IP mapping, and thus cannot bypass authentication for domain users, causing them to be prompted for credentials when accessing the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The FortiGate is not polling the AD domain controllers

    Why this is correct

    In FSSO polling mode, the FortiGate acts as a collector agent: it periodically connects to Active Directory domain controllers over LDAP, queries for user logon events (e.g., event ID 4624), and builds a mapping between authenticated usernames and their source IP addresses. If polling is not configured (or the service account's credentials are invalid, or the polling interval is mis-set), the FortiGate never receives that mapping. Consequently, the security policy cannot correlate the incoming traffic with any FSSO user group, so the session is treated as unauthenticated and falls through to the default deny/action rather than prompting for credentials.

  • ✗

    The users are using non-Windows machines

    Why it's wrong here

    FSSO is designed to be independent of the client operating system. The only prerequisite is that the user authenticates to the Active Directory domain — whether from Windows, macOS, Linux, or even a mobile device via a web sign-in. In the modern FSSO agent-based architecture, the FortiGate or a dedicated collector agent watches domain controller security logs regardless of the client OS that generated the logon event. Therefore, users on non-Windows machines will still appear in the FSSO mapping as long as their logon reaches AD.

  • ✗

    The firewall policy does not have FSSO authentication enabled

    Why it's wrong here

    An FSSO-enabled firewall policy does not challenge the user for credentials; its entire purpose is to provide transparent, single-sign-on identity enforcement. If the policy lacked FSSO authentication (i.e., it was an ordinary address-based policy), FortiGate would simply match source/destination IPs and apply the configured action — it would never present a login prompt. A prompt for manual credentials is a hallmark of policy-based authentication or captive portal, not of FSSO. Thus, a missing FSSO setting could not cause the observed behavior.

  • ✗

    The FortiGate is not joined to the domain

    Why it's wrong here

    FSSO polling (also called 'mode 1' or 'direct polling') uses LDAP to query the domain controllers, so the FortiGate only needs network reachability and a valid service account belonging to the domain. The FortiGate does not need a computer account nor does it need to be joined to the AD domain. Even in agent-based mode, the FortiGate simply communicates with the FSSO agent over TCP/8000 and never needs domain membership. Therefore, an unjoined FortiGate can still successfully map users via FSSO as long as the domain controller queries succeed.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.