NSE4 Authentication and VPN Practice Question
An administrator is configuring a FortiGate to use LDAP for firewall authentication. Users are prompted for their credentials when accessing the internet. After successful authentication, users can access the internet. However, the administrator notices that users are prompted again after 30 minutes of inactivity. Which setting should the administrator adjust to extend the authentication timeout?
⚠ Common exam trap
Many candidates confuse session timeouts with authentication timeouts, but the re-prompting after 30 minutes is specifically governed by the authentication timeout setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the 'auth-timeout' in the user settings.
The authentication timeout on a FortiGate is controlled by the 'auth-timeout' setting, which can be configured globally or per user group. This setting determines how long a user remains authenticated after providing credentials. The default is 30 minutes. To extend this period, the administrator should increase the 'auth-timeout' value. Other timeouts, such as idle-timeout or session-ttl, affect session behavior but not the authentication duration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the 'idle-timeout' in the firewall policy.
Why it's wrong here
The 'idle-timeout' in a firewall policy controls how long a session can remain idle before it is closed. It does not control the authentication timeout for the user. The authentication timeout is a separate setting that determines how long a user remains authenticated after logging in, regardless of session activity.
- ✓
Modify the 'auth-timeout' in the user settings.
Why this is correct
The 'auth-timeout' setting under 'config system global' or per-user group controls how long a user's authentication is valid. By default, it is 30 minutes. Increasing this value will extend the time before users are prompted to re-authenticate. This is the correct setting to adjust for extending the authentication period.
- ✗
Adjust the 'session-ttl' in the firewall policy.
Why it's wrong here
The 'session-ttl' defines the maximum lifetime of a session, after which it is closed regardless of activity. It is not related to authentication timeout. Changing it would not extend the authentication period; it could even cause sessions to terminate earlier if set too low.
- ✗
Change the 'ldap-timeout' in the LDAP server configuration.
Why it's wrong here
The 'ldap-timeout' setting specifies how long the FortiGate waits for a response from the LDAP server during authentication. It does not affect how long a user remains authenticated. Adjusting this would not prevent re-prompting after 30 minutes; it would only affect the initial authentication process.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.