Courseiva

NSE4 System and Network Administration Practice Question

An administrator is configuring a FortiGate to authenticate users via LDAP. The LDAP server uses a self-signed certificate. When testing the connection, the FortiGate returns an error about certificate validation. Which action should the administrator take to resolve this issue while maintaining security?

⚠ Common exam trap

The trap here is choosing to disable certificate validation for convenience, which compromises security, instead of importing the CA certificate to establish trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Import the LDAP server's CA certificate into the FortiGate's local certificate store and configure the LDAP server to use LDAPS.

The certificate validation error occurs because the FortiGate does not trust the self-signed certificate of the LDAP server. Importing the CA certificate into the FortiGate's local store allows it to validate the server's certificate. Configuring LDAPS ensures the connection is encrypted. This maintains security without disabling validation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable certificate validation on the FortiGate for LDAP connections.

    Why it's wrong here

    Disabling certificate validation would allow the connection to proceed but eliminates security, making the FortiGate vulnerable to man-in-the-middle attacks. This is not acceptable when security is a requirement. The administrator should instead import the CA certificate to enable validation.

  • ✗

    Set the LDAP server to use port 389 with StartTLS and enable certificate validation.

    Why it's wrong here

    StartTLS on port 389 can provide encryption, but the certificate validation error would persist unless the CA is trusted. The issue is not the port or protocol but the untrusted certificate. The administrator must import the CA certificate regardless of using LDAPS or StartTLS.

  • ✓

    Import the LDAP server's CA certificate into the FortiGate's local certificate store and configure the LDAP server to use LDAPS.

    Why this is correct

    Importing the CA certificate allows the FortiGate to validate the LDAP server's certificate. Using LDAPS ensures encryption. This maintains security by verifying the server's identity. The FortiGate must trust the CA that signed the LDAP server's certificate. This is the correct approach to resolve certificate validation errors while keeping the connection secure.

  • ✗

    Configure the LDAP server to use a public CA-signed certificate instead of a self-signed one.

    Why it's wrong here

    While using a public CA-signed certificate would resolve validation issues, it requires changes on the LDAP server and may not be feasible. The question asks for an action on the FortiGate to resolve the issue while maintaining security. Importing the self-signed CA is more direct and does not require altering the LDAP server.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.