NSE4 Authentication and VPN Practice Question
A FortiGate administrator is configuring a new SSL VPN portal for employees. The requirement is that employees must authenticate using their Active Directory credentials, and after authentication, they should only be able to access a specific internal web server via a bookmarked link. Which SSL VPN configuration should the administrator use to meet these requirements?
⚠ Common exam trap
The trap here is assuming that tunnel mode is always required for internal access, when web mode with bookmarks is sufficient and more secure for specific web applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the SSL VPN settings to use 'Web Mode' and add a bookmark to the portal for the internal web server.
Web mode is designed for browser-based access to specific applications, and bookmarks provide easy links to internal web servers. Authentication can be configured to use Active Directory, satisfying the credential requirement. Tunnel mode would provide broader network access than needed and does not use bookmarks for specific applications. Therefore, web mode with a bookmark and AD authentication is the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the SSL VPN settings to use 'Web Mode' and add a bookmark to the portal for the internal web server.
Why this is correct
Web mode allows users to access specific web-based applications through a portal without a full tunnel. By adding a bookmark to the internal web server, users can click the link to access it. Authentication can be set to use Active Directory. This meets the requirements of AD authentication and limited access to a specific web server via a bookmark.
- ✗
Configure the SSL VPN settings to use 'Web Mode' and enable 'Client Certificate' authentication.
Why it's wrong here
Client certificate authentication is not required; the requirement is to use Active Directory credentials. Enabling client certificate authentication would add an additional authentication factor that is not requested and could complicate access. While web mode is correct, the authentication method must be AD, not client certificates. This option would not meet the authentication requirement.
- ✗
Configure the SSL VPN settings to use 'Tunnel Mode' with split tunneling and add a static route for the web server.
Why it's wrong here
Split tunneling with tunnel mode still provides network-level access, not just a bookmark. While it can limit which subnets are routed, it does not provide a bookmark-based access method. The requirement specifically mentions a bookmarked link, which is a feature of web mode. This option would be more complex and would not restrict access as precisely as web mode.
- ✗
Configure the SSL VPN settings to use 'Tunnel Mode' and create a firewall policy allowing all internal subnets.
Why it's wrong here
Tunnel mode provides full network access and would not restrict users to a specific web server. It also requires more complex routing and firewall policies. The requirement is to provide access only to a specific web server via a bookmark, which is better suited to web mode. Tunnel mode would grant broader access than intended and does not use bookmarks for specific applications.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.