Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

An administrator has configured LDAP authentication on a FortiGate. When testing the LDAP connectivity, the test succeeds. However, users cannot authenticate through the captive portal. What is a possible cause?

⚠ Common exam trap

It's easy for candidates to assume a successful LDAP connectivity test guarantees full authentication functionality, but FortiGate requires an explicit user group binding to use the LDAP server for captive portal authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user group is not configured to use the LDAP server

The LDAP connectivity test succeeds, confirming the FortiGate can reach and bind to the LDAP server. However, for captive portal authentication to work, the user group must be explicitly configured to reference the LDAP server as its remote authentication source. Without this mapping, the FortiGate does not know to send authentication requests to the LDAP server, even though the LDAP server connection itself is functional.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The captive portal is disabled

    Why it's wrong here

    Disabling the captive portal would remove the authentication landing page entirely, so users would not even see a login prompt for LDAP credentials. On FortiGate, the captive portal is the front-end that intercepts unauthenticated web traffic and presents the login form; without it, the authentication flow never begins. Since the administrator is likely seeing a login page but authentication fails, a disabled captive portal is not the underlying cause.

  • ✓

    The user group is not configured to use the LDAP server

    Why this is correct

    In FortiGate, an LDAP server object alone is not sufficient for authentication; the user group must explicitly reference that LDAP server as its remote authentication source. When a user tries to authenticate via the captive portal, FortiGate checks the user's group membership and looks at the authentication server assigned to that group. If the LDAP server is not configured in the user group settings, FortiGate has no source to bind against, so the LDAP query is never performed. This is the correct root cause because it explains why connectivity to LDAP succeeds but authentication still fails.

  • ✗

    The LDAP server is not reachable from the captive portal interface

    Why it's wrong here

    A successful LDAP connectivity test from the FortiGate already verifies that the server is reachable and that the configured bind credentials work. The captive portal is a local FortiGate feature and does not have a separate routing path to the LDAP server; it uses the same FortiGate interface and routing table. Therefore, if the connectivity test passes, the LDAP server is inherently reachable from the captive portal's context, making this option incorrect.

  • ✗

    The LDAP server's SSL certificate is expired

    Why it's wrong here

    An expired SSL certificate would only affect LDAPS (LDAP over SSL/TLS) connections, and FortiGate would typically display a certificate validation error or fail during the connectivity test. Since the administrator has tested LDAP connectivity successfully, the certificate chain must be valid and trusted by the FortiGate. Moreover, if plain LDAP (port 389) is configured, SSL certificate expiration is irrelevant to authentication altogether. Thus, an expired certificate cannot be the reason for authentication failure after a successful connectivity test.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.