NSE4 System and Network Administration Practice Question
An administrator is configuring a FortiGate to authenticate users via LDAP. The LDAP server uses a self-signed certificate. When testing the connection, the FortiGate returns an error about certificate validation. Which action should the administrator take to resolve this issue while maintaining security?
⚠ Common exam trap
The trap here is choosing to disable certificate validation for convenience, which compromises security, instead of importing the CA certificate to establish trust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Import the LDAP server's CA certificate into the FortiGate's local certificate store and configure the LDAP server to use LDAPS.
The certificate validation error occurs because the FortiGate does not trust the self-signed certificate of the LDAP server. Importing the CA certificate into the FortiGate's local store allows it to validate the server's certificate. Configuring LDAPS ensures the connection is encrypted. This maintains security without disabling validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable certificate validation on the FortiGate for LDAP connections.
Why it's wrong here
Disabling certificate validation would allow the connection to proceed but eliminates security, making the FortiGate vulnerable to man-in-the-middle attacks. This is not acceptable when security is a requirement. The administrator should instead import the CA certificate to enable validation.
- ✗
Set the LDAP server to use port 389 with StartTLS and enable certificate validation.
Why it's wrong here
StartTLS on port 389 can provide encryption, but the certificate validation error would persist unless the CA is trusted. The issue is not the port or protocol but the untrusted certificate. The administrator must import the CA certificate regardless of using LDAPS or StartTLS.
- ✓
Import the LDAP server's CA certificate into the FortiGate's local certificate store and configure the LDAP server to use LDAPS.
Why this is correct
Importing the CA certificate allows the FortiGate to validate the LDAP server's certificate. Using LDAPS ensures encryption. This maintains security by verifying the server's identity. The FortiGate must trust the CA that signed the LDAP server's certificate. This is the correct approach to resolve certificate validation errors while keeping the connection secure.
- ✗
Configure the LDAP server to use a public CA-signed certificate instead of a self-signed one.
Why it's wrong here
While using a public CA-signed certificate would resolve validation issues, it requires changes on the LDAP server and may not be feasible. The question asks for an action on the FortiGate to resolve the issue while maintaining security. Importing the self-signed CA is more direct and does not require altering the LDAP server.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.