Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

An administrator needs to configure two-factor authentication for SSL VPN users using FortiToken. Which configuration is required on the FortiGate?

⚠ Common exam trap

Candidates often assume two-factor authentication is a global setting or that installing the app on the FortiGate is required, when in fact it is a per-user configuration combined with an authentication scheme and rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable FortiToken on the user account and configure the authentication scheme to require token

FortiGate requires two-factor authentication to be enabled on the user account itself (via the 'Two-factor Authentication' field set to 'FortiToken') and then an authentication scheme must be configured that includes a 'Token' requirement. This ensures that the user must provide both their password and a one-time token from the FortiToken device or app during SSL VPN login.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable two-factor authentication globally on the FortiGate

    Why it's wrong here

    FortiGate does not provide a global two-factor toggle; enforcing two-factor is a property of the individual user object and the authentication scheme that the security policy invokes. Enabling it globally would require modifying every local or remote user entry anyway, and there is no such CLI/GUI master switch. Consequently, even if an administrator wanted every login to demand a token, it must be configured per user account or per authentication rule.

  • ✓

    Enable FortiToken on the user account and configure the authentication scheme to require token

    Why this is correct

    To enforce two-factor, assign a FortiToken to the user account in the user definition (e.g., register the FortiToken Mobile seed) and then set the required authentication method in the authentication scheme to 'FortiToken' or 'Token-based'. The scheme, not the firewall policy, defines how many and which authentication factors are accepted, and this scheme is then referenced by the security policy using identity-based authentication. Without assigning the token and enforcing it in the scheme, merely having the app installed does nothing.

  • ✗

    Install the FortiToken mobile app on the FortiGate

    Why it's wrong here

    The FortiToken mobile application is deployed on a smartphone or tablet that belongs to the end user, and it generates time-based one-time passwords from a seed that is registered on FortiGate. Installing it on the FortiGate itself is conceptually impossible because the FortiGate is the authentication server, not a proof-of-possession device, and installation would not provide the user with a token. The administrator instead must activate and assign the token to the user so the FortiGate can validate the dynamic code.

  • ✗

    Create a separate firewall policy for token-based authentication

    Why it's wrong here

    A separate firewall policy is unnecessary because identity-based authentication policies reference an authentication scheme that already determines whether token verification is required; one policy can serve users who authenticate with or without a token depending on the scheme's actions. Two-factor enforcement is not a per-policy attribute, so creating a new policy for token users adds administrative overhead without changing the authentication flow. The policy's role is to select the correct authentication scheme and then apply access control after the user's identity and token are successfully verified.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.