Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

An administrator configures an LDAP user group for firewall authentication. Users are able to authenticate, but the FortiGate does not retrieve group membership information. What is likely misconfigured?

⚠ Common exam trap

Many candidates assume authentication success means all LDAP functions work, but Fortinet specifically tests the distinction between authentication (bind) and attribute retrieval (search), which require different permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The LDAP bind account does not have permission to read group attributes

The LDAP bind account must have sufficient permissions to read the memberOf or group membership attributes from the directory. If the bind account can authenticate users but cannot query group membership, the FortiGate will not be able to enforce policies based on LDAP groups. This is the most common cause when authentication succeeds but group information is missing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The LDAP server's IP address is incorrect

    Why it's wrong here

    The LDAP server's IP address being incorrect would prevent the FortiGate from establishing any TCP connection to the LDAP service, resulting in a timeout or connection refused during the authentication attempt. Since the administrator can successfully authenticate, the FortiGate has already reached the LDAP server and completed a bind operation, proving that the IP address and network path are correctly configured. Thus, an incorrect IP cannot explain the absence of group membership data.

  • ✗

    SSL is not enabled for LDAP

    Why it's wrong here

    SSL/TLS encryption is an optional transport security feature for LDAP, not a prerequisite for directory reads. The FortiGate can perform unencrypted LDAP binds and searches over port 389 or use StartTLS, and group attributes such as memberOf or member are still retrievable over plaintext connections if the directory server permits it. Therefore, disabling SSL would only raise confidentiality concerns; it would not prevent the group lookup from returning results, so this cannot be the cause of the missing user group.

  • ✓

    The LDAP bind account does not have permission to read group attributes

    Why this is correct

    When the FortiGate authenticates a user via LDAP, it also performs a directory search to resolve that user's group memberships, using the credentials of the configured bind account. If the bind account has permission to read the user object but lacks read access to the group objects or their membership attributes (e.g., memberOf, uniqueMember, member), the LDAP search returns an empty or partial result. Because the FortiGate builds its firewall user groups from these returned attributes, insufficient read privileges on group data directly cause the correct behavior that the administrator is seeing: authentication succeeds, but no matching LDAP group is found.

  • ✗

    The FortiGate is not joined to the domain

    Why it's wrong here

    LDAP authentication and group retrieval are entirely separate from the concept of joining an Active Directory domain. The FortiGate operates as an LDAP client using only the server's address, bind credentials, and search base; it does not need to be part of the domain, authenticate with Kerberos, or receive domain policies. A domain join is only relevant for features like FSSO or domain controller discovery, so the absence of a domain join does not prevent the LDAP server from responding to group queries or returning group attributes.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.