Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

A FortiGate administrator needs to authenticate VPN users against an LDAP server. What is the primary purpose of the 'CN=,OU=,DC=' distinguished name (DN) configured in the LDAP server settings?

⚠ Common exam trap

A common mix-up: candidates confuse the bind DN (used for authenticating the FortiGate to the LDAP server) with the base DN (used for searching user objects), leading them to incorrectly select Option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It specifies the bind user credentials to connect to the LDAP server

The DN configured in the LDAP server settings on FortiGate specifies the bind user credentials (username and password) that the FortiGate uses to authenticate itself to the LDAP server before performing user searches. This bind DN is required because LDAP servers typically require a valid authenticated session to query the directory; the bind DN provides the necessary identity and privileges for the FortiGate to search for VPN users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is used to encrypt LDAP communication

    Why it's wrong here

    The DN field is not used for encryption. LDAP traffic is secured separately via LDAPS (port 636) or StartTLS (port 389) settings; the FortiGate does not derive encryption parameters from the bind DN. Encryption protects data in transit, whereas the DN is a credential identifier for the bind operation.

  • ✗

    It defines the IP address of the LDAP server

    Why it's wrong here

    The server's IP address or hostname is configured in a dedicated 'Server IP/Name' field in the LDAP server settings, not in the DN field. A DN is a directory entry identifier (e.g., cn=admin,dc=example,dc=com), which is semantically unrelated to network addressing. Setting an IP address as the DN would cause authentication to fail because it does not reference a valid LDAP object.

  • ✗

    It specifies the base DN for searching users

    Why it's wrong here

    The base DN, which defines the search subtree for user lookups (e.g., ou=Users,dc=example,dc=com), is a separate configuration parameter. The DN in question is the bind user's distinguished name, which specifies a single directory entry used to authenticate the FortiGate. Confusing the two prevents successful LDAP queries, as the bind operation would use an inappropriate scope.

  • ✓

    It specifies the bind user credentials to connect to the LDAP server

    Why this is correct

    The DN and the associated password serve as the bind user credentials. When the FortiGate connects to the LDAP server, it performs a bind operation using this DN and password to authenticate itself before it can search for VPN users. This account must have read privileges over the user subtree to enable successful authentication and group lookups.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.