Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

An administrator is configuring a FortiGate to use LDAP for firewall authentication. Users are prompted for their credentials when accessing the internet. After successful authentication, users can access the internet. However, the administrator notices that users are prompted again after 30 minutes of inactivity. Which setting should the administrator adjust to extend the authentication timeout?

⚠ Common exam trap

Many candidates confuse session timeouts with authentication timeouts, but the re-prompting after 30 minutes is specifically governed by the authentication timeout setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the 'auth-timeout' in the user settings.

The authentication timeout on a FortiGate is controlled by the 'auth-timeout' setting, which can be configured globally or per user group. This setting determines how long a user remains authenticated after providing credentials. The default is 30 minutes. To extend this period, the administrator should increase the 'auth-timeout' value. Other timeouts, such as idle-timeout or session-ttl, affect session behavior but not the authentication duration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the 'idle-timeout' in the firewall policy.

    Why it's wrong here

    The 'idle-timeout' in a firewall policy controls how long a session can remain idle before it is closed. It does not control the authentication timeout for the user. The authentication timeout is a separate setting that determines how long a user remains authenticated after logging in, regardless of session activity.

  • ✓

    Modify the 'auth-timeout' in the user settings.

    Why this is correct

    The 'auth-timeout' setting under 'config system global' or per-user group controls how long a user's authentication is valid. By default, it is 30 minutes. Increasing this value will extend the time before users are prompted to re-authenticate. This is the correct setting to adjust for extending the authentication period.

  • ✗

    Adjust the 'session-ttl' in the firewall policy.

    Why it's wrong here

    The 'session-ttl' defines the maximum lifetime of a session, after which it is closed regardless of activity. It is not related to authentication timeout. Changing it would not extend the authentication period; it could even cause sessions to terminate earlier if set too low.

  • ✗

    Change the 'ldap-timeout' in the LDAP server configuration.

    Why it's wrong here

    The 'ldap-timeout' setting specifies how long the FortiGate waits for a response from the LDAP server during authentication. It does not affect how long a user remains authenticated. Adjusting this would not prevent re-prompting after 30 minutes; it would only affect the initial authentication process.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.