NSE4 Authentication and VPN Practice Question
An organization uses LDAP authentication for firewall policies. Users complain that they are frequently prompted for credentials. Which TWO settings can reduce the frequency of authentication prompts?
⚠ Common exam trap
A common mix-up: candidates confuse the LDAP server's idle timeout (a connection keepalive) with the firewall's authentication timeout (a cached credential timer), leading them to incorrectly select Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the authentication timeout on the firewall policy.
Increasing the authentication timeout on the firewall policy (Option A) allows the firewall to cache the user's authentication state for a longer period, so users are not re-prompted for credentials as frequently when traffic matches that policy. Enabling single sign-on (SSO) authentication (Option C) leverages Kerberos or NTLM to automatically authenticate users based on their domain logon, eliminating repeated manual credential prompts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase the authentication timeout on the firewall policy.
Why this is correct
Increasing the authentication timeout on the firewall policy extends how long an LDAP-authenticated user's session remains valid before the FortiGate forces a re-authentication. After successful LDAP validation, the firewall caches the user's access rights for the duration of this timeout; once it expires, the user must re-enter credentials for that policy. A longer timeout reduces the frequency of prompts, but it also widens the security window in which a session could be hijacked or reused by an unauthorized user on a shared machine. This is the direct, policy-level control that governs prompt frequency.
- ✗
Increase the idle timeout on the LDAP server.
Why it's wrong here
The LDAP server's idle timeout specifies how long an unresolved LDAP connection can stay open without activity before the server closes it. This is a server-side TCP connection parameter that affects connection pooling or resource cleanup, not the FortiGate's authentication session cache. Changing it has no impact on the firewall policy's authentication timeout, which is the sole determiner of when a user is prompted again after a successful LDAP authentication. Therefore, adjusting LDAP idle timeout is irrelevant to reducing user authentication prompts on the firewall.
- ✓
Enable single sign-on (SSO) authentication method.
Why this is correct
Enabling single sign-on (SSO) authentication method, such as FSSO with a Collector Agent, lets the FortiGate receive Windows Active Directory login events and associate users with trusted sessions without requiring a separate firewall login page. The user authenticates once at the domain workstation, and the firewall validates the session against AD group memberships, so it does not need to prompt for LDAP credentials on each policy match. SSO caches the domain session state on the FortiGate, dramatically reducing or eliminating repeated username/password prompts. This approach shifts authentication frequency from the firewall policy cycle to the domain logon session, improving user experience while maintaining access control.
- ✗
Disable captive portal on the interface.
Why it's wrong here
Disabling the captive portal on an interface would remove the web-based login page that the FortiGate uses to present authentication challenges for HTTP/HTTPS traffic in certain policy configurations. However, the captive portal is not the mechanism that determines how often users must re-authenticate for LDAP-backed policies; that cadence is set by the firewall policy's authentication timeout. If you disable the captive portal, you do not lower the prompt frequency—instead, you risk breaking the interactive login flow entirely, making it impossible for users to authenticate when a policy requires it. The portal is a presentation layer, not the timer that governs re-authentication intervals.
- ✗
Use a longer password for LDAP accounts.
Why it's wrong here
The length or complexity of the LDAP account password affects password strength and server-side expiration policies, but it has no relation to the FortiGate's authentication timeout or how often a user is prompted for authentication. Prompt frequency on firewall policies is controlled solely by the policy-level authentication timeout, not by anything about the credential itself. A longer password does not alter the cache life of a successful LDAP authentication on the firewall. Thus, this option would have zero effect on reducing the number of authentication prompts and is an incorrect remedy for the issue.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.