Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

A FortiGate administrator is configuring a new SSL VPN portal for employees. The requirement is that employees must authenticate using their Active Directory credentials, and after authentication, they should only be able to access a specific internal web server via a bookmarked link. Which SSL VPN configuration should the administrator use to meet these requirements?

⚠ Common exam trap

The trap here is assuming that tunnel mode is always required for internal access, when web mode with bookmarks is sufficient and more secure for specific web applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the SSL VPN settings to use 'Web Mode' and add a bookmark to the portal for the internal web server.

Web mode is designed for browser-based access to specific applications, and bookmarks provide easy links to internal web servers. Authentication can be configured to use Active Directory, satisfying the credential requirement. Tunnel mode would provide broader network access than needed and does not use bookmarks for specific applications. Therefore, web mode with a bookmark and AD authentication is the correct solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the SSL VPN settings to use 'Web Mode' and add a bookmark to the portal for the internal web server.

    Why this is correct

    Web mode allows users to access specific web-based applications through a portal without a full tunnel. By adding a bookmark to the internal web server, users can click the link to access it. Authentication can be set to use Active Directory. This meets the requirements of AD authentication and limited access to a specific web server via a bookmark.

  • ✗

    Configure the SSL VPN settings to use 'Web Mode' and enable 'Client Certificate' authentication.

    Why it's wrong here

    Client certificate authentication is not required; the requirement is to use Active Directory credentials. Enabling client certificate authentication would add an additional authentication factor that is not requested and could complicate access. While web mode is correct, the authentication method must be AD, not client certificates. This option would not meet the authentication requirement.

  • ✗

    Configure the SSL VPN settings to use 'Tunnel Mode' with split tunneling and add a static route for the web server.

    Why it's wrong here

    Split tunneling with tunnel mode still provides network-level access, not just a bookmark. While it can limit which subnets are routed, it does not provide a bookmark-based access method. The requirement specifically mentions a bookmarked link, which is a feature of web mode. This option would be more complex and would not restrict access as precisely as web mode.

  • ✗

    Configure the SSL VPN settings to use 'Tunnel Mode' and create a firewall policy allowing all internal subnets.

    Why it's wrong here

    Tunnel mode provides full network access and would not restrict users to a specific web server. It also requires more complex routing and firewall policies. The requirement is to provide access only to a specific web server via a bookmark, which is better suited to web mode. Tunnel mode would grant broader access than intended and does not use bookmarks for specific applications.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.