NSE4 Authentication and VPN Practice Question
An administrator has configured LDAP authentication on a FortiGate. When testing the LDAP connectivity, the test succeeds. However, users cannot authenticate through the captive portal. What is a possible cause?
⚠ Common exam trap
It's easy for candidates to assume a successful LDAP connectivity test guarantees full authentication functionality, but FortiGate requires an explicit user group binding to use the LDAP server for captive portal authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user group is not configured to use the LDAP server
The LDAP connectivity test succeeds, confirming the FortiGate can reach and bind to the LDAP server. However, for captive portal authentication to work, the user group must be explicitly configured to reference the LDAP server as its remote authentication source. Without this mapping, the FortiGate does not know to send authentication requests to the LDAP server, even though the LDAP server connection itself is functional.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The captive portal is disabled
Why it's wrong here
Disabling the captive portal would remove the authentication landing page entirely, so users would not even see a login prompt for LDAP credentials. On FortiGate, the captive portal is the front-end that intercepts unauthenticated web traffic and presents the login form; without it, the authentication flow never begins. Since the administrator is likely seeing a login page but authentication fails, a disabled captive portal is not the underlying cause.
- ✓
The user group is not configured to use the LDAP server
Why this is correct
In FortiGate, an LDAP server object alone is not sufficient for authentication; the user group must explicitly reference that LDAP server as its remote authentication source. When a user tries to authenticate via the captive portal, FortiGate checks the user's group membership and looks at the authentication server assigned to that group. If the LDAP server is not configured in the user group settings, FortiGate has no source to bind against, so the LDAP query is never performed. This is the correct root cause because it explains why connectivity to LDAP succeeds but authentication still fails.
- ✗
The LDAP server is not reachable from the captive portal interface
Why it's wrong here
A successful LDAP connectivity test from the FortiGate already verifies that the server is reachable and that the configured bind credentials work. The captive portal is a local FortiGate feature and does not have a separate routing path to the LDAP server; it uses the same FortiGate interface and routing table. Therefore, if the connectivity test passes, the LDAP server is inherently reachable from the captive portal's context, making this option incorrect.
- ✗
The LDAP server's SSL certificate is expired
Why it's wrong here
An expired SSL certificate would only affect LDAPS (LDAP over SSL/TLS) connections, and FortiGate would typically display a certificate validation error or fail during the connectivity test. Since the administrator has tested LDAP connectivity successfully, the certificate chain must be valid and trusted by the FortiGate. Moreover, if plain LDAP (port 389) is configured, SSL certificate expiration is irrelevant to authentication altogether. Thus, an expired certificate cannot be the reason for authentication failure after a successful connectivity test.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.