Courseiva
Authentication and VPN →mediumMultiple Select

NSE4 Authentication and VPN Practice Question

A FortiGate administrator is configuring FSSO to authenticate users transparently. The FSSO collector agent is installed on a Windows server in the domain. Which TWO requirements must be met for FSSO to work correctly?

⚠ Common exam trap

Watch out — candidates often assume the FortiGate must join the Active Directory domain (Option A), but FSSO only requires network connectivity to the collector agent, not domain membership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate must be able to reach the FSSO collector agent on TCP port 8000 (or the configured port)

The FortiGate must communicate with the FSSO collector agent over TCP port 8000 (or a custom port) to receive real-time user login/logoff events. This connection is essential for the FortiGate to map IP addresses to authenticated domain users and enforce identity-based firewall policies. Without this reachability, the FortiGate cannot obtain the necessary user-to-IP mappings from the collector agent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate must be a member of the Active Directory domain

    Why it's wrong here

    The FortiGate does not need to join the Active Directory domain for FSSO to operate. Only the FSSO collector agent requires domain access, because it is the component that reads authentication events from the domain controllers. The FortiGate simply receives the resulting user-to-IP mappings via a TCP connection, so domain membership would be redundant and is only relevant for features like AD VPN SSO.

  • ✗

    The users must authenticate via captive portal at least once

    Why it's wrong here

    FSSO is designed to monitor existing Active Directory logins without user interaction. Users authenticate once to their Windows workstation, and the collector agent forwards that event to the FortiGate automatically; no captive portal is ever involved. Captive portal would instead be a separate method for unauthenticated users, not a prerequisite for FSSO.

  • ✓

    The FortiGate must be able to reach the FSSO collector agent on TCP port 8000 (or the configured port)

    Why this is correct

    The FortiGate must be able to reach the FSSO collector agent on TCP port 8000 (or the port specified under FSSO settings). This is the connection over which the collector agent sends login and logout events; if the port is firewalled, the FortiGate will not receive authentication updates and FSSO policies will fail to match. The default port is 8000, but it must match exactly on both the agent and the FortiGate.

  • ✗

    The firewall policies must use FSSO groups directly without any user objects

    Why it's wrong here

    Firewall policies in an FSSO deployment can reference FSSO groups, but they do not have to use only groups to the exclusion of user objects. A policy can include an individual user object created from LDAP, or a group that is not FSSO-sourced; the key requirement is that the authentication source for the user session is FSSO, not the object type used in the policy rule. Thus, the claim that no user objects can be used is incorrect.

  • ✓

    The FSSO collector agent must have network access to the Active Directory domain controllers

    Why this is correct

    The FSSO collector agent depends on network access to the Active Directory domain controllers to capture logon events. In polling mode it queries the DCs for security event logs; in DC agent mode it receives events from a service installed on the DCs. Without this connectivity, no user authentication events are collected, so the FortiGate will have no user-to-IP mappings to apply FSSO policies.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.