Courseiva

NSE4 · topic practice

Authentication and VPN practice questions

This domain covers FortiGate authentication and VPN configuration and troubleshooting, roughly 20% of the NSE4 exam. Expect scenario questions on IPsec Phase 1/Phase 2, dial-up VPNs, SSL VPN, user groups, captive portal, and FortiClient. You must interpret diagnose commands and debug output to isolate failures.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Authentication and VPN

What the exam tests

What to know about Authentication and VPN

Be able to configure and troubleshoot IPsec and SSL VPN authentication on FortiGate. The single most important skill is using diagnose vpn ike config, diagnose vpn tunnel list, and IKE debug to determine why a tunnel or user traffic fails.

Interpreting 'diagnose vpn ike config' output, including peer-id: any meaning

Captive portal purpose for authenticating users before granting network access

Troubleshooting dial-up IPsec VPNs where Phase 1 and Phase 2 are up

Reading 'diagnose debug application ike -1' and 'diagnose vpn tunnel list' output

Watch out for

Common Authentication and VPN exam traps

  • ▸Assuming Phase 1 and Phase 2 'up' means traffic passes; routing, firewall policy, or selectors may still block it.
  • ▸Misreading 'peer-id: any' as an error; it means the FortiGate accepts any peer identifier during IKE negotiation.
  • ▸Confusing captive portal authentication with SSL VPN portal; captive portal controls web access, not tunnel establishment.

Practice set

Authentication and VPN questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Read the full VPN explanation →

Refer to the exhibit. A network administrator configured an IPsec VPN between the main office and a branch office. Remote users at the branch office report that they cannot access resources in the main office. The tunnel status shows up on both sides. What is the most likely cause of the connectivity issue?

Exhibit

Refer to the exhibit.
config vpn ipsec phase1-interface
    edit "to_Branch"
        set interface "wan1"
        set ike-version 2
        set keylife 86400
        set peertype any
        set net-device disable
        set mode-cfg enable
        set proposal aes256-sha256
        set dhgroup 14
        set remote-gw 203.0.113.5
        set psksecret ENC ...
    next
end
config vpn ipsec phase2-interface
    edit "to_Branch_p2"
        set phase1name "to_Branch"
        set proposal aes256-sha256
        set pfs enable
        set dhgrp 14
        set auto-negotiate enable
        set keylifeseconds 3600
    next
end
Question 2mediummatching
Read the full VPN explanation →

Match each FortiGate VPN type to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Connects two networks over the internet securely

Provides remote access via web browser or client software

Legacy VPN protocol with weaker security

Combines Layer 2 tunneling with IPsec encryption

Auto-discovery VPN that dynamically establishes shortcuts

Question 3hardmultiple choice
Read the full VPN explanation →

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

Question 4mediummultiple choice
Read the full VPN explanation →

An administrator configures an SSL VPN portal with web mode and split tunneling enabled. Remote users can access internal web applications but cannot reach the internet through the VPN. What needs to be checked?

Question 5mediummulti select
Read the full VPN explanation →

An administrator needs to configure a hub-and-spoke IPsec VPN topology. Which TWO settings must be configured on the hub FortiGate to allow spokes to communicate with each other through the hub?

Question 6hardmulti select
Read the full VPN explanation →

A FortiGate administrator is troubleshooting an SSL VPN issue where users can authenticate but cannot access any internal resources. The SSL VPN status shows 'connected'. Which THREE commands or actions should be used to diagnose the problem?

Question 7easymultiple choice
Read the full VPN explanation →

A FortiGate administrator wants to enforce two-factor authentication for SSL VPN users. The organization uses FortiToken mobile tokens. What must be configured on the FortiGate to enable FortiToken authentication?

Question 8mediummulti select
Read the full VPN explanation →

A FortiGate administrator is configuring an SSL VPN tunnel mode for remote users. The administrator wants to ensure that only traffic destined for the corporate network (192.168.1.0/24) goes through the VPN, and all other traffic (e.g., internet) goes directly from the user's device. Which TWO configuration steps are required?

Question 9mediummulti select
Read the full VPN explanation →

A network admin is configuring a hub-and-spoke VPN with three spokes. Which TWO statements are correct about route-based VPN in this topology?

Question 10mediummultiple choice
Read the full VPN explanation →

An administrator wants to enable two-factor authentication for SSL VPN users using FortiToken. Which configuration is required on the FortiGate?

Question 11mediummultiple choice
Read the full VPN explanation →

A FortiGate administrator is setting up a dial-up IPsec VPN for remote employees. Each employee uses a FortiClient. Which authentication method should be used to allow individual user identities?

Question 12mediummultiple choice
Read the full VPN explanation →

A network administrator has configured an IPsec VPN between two FortiGate devices. The Phase 1 proposal includes AES256-SHA256-DH14. The Phase 2 proposal includes AES128-SHA1. The VPN tunnel fails to establish. Which of the following is the MOST likely cause?

Question 13mediummultiple choice
Read the full VPN explanation →

An administrator has configured an SSL VPN. Remote users can connect and authenticate but cannot access internal resources. The SSL VPN policy allows all traffic from the SSL VPN interface to internal servers. What is the MOST likely missing configuration?

Question 14mediummultiple choice
Read the full VPN explanation →

An administrator needs to configure a site-to-site IPsec VPN where both sites have dynamic public IP addresses. Which IKE mode should be used?

Question 15hardmulti select
Read the full VPN explanation →

A company has multiple branch offices connected via IPsec VPN in a hub-and-spoke topology. They want to enable direct communication between branch offices without routing traffic through the hub. Which THREE configurations are required on the hub FortiGate? (Choose three.)

Question 16easymulti select
Read the full VPN explanation →

An administrator wants to configure two-factor authentication for SSL VPN users. Which TWO components must be configured? (Choose two.)

Question 17mediummultiple choice
Read the full VPN explanation →

A captive portal is configured on a FortiGate to authenticate users before allowing internet access. Users report that after entering credentials, they are redirected to the original website, but then they cannot access other sites. What is the most likely issue?

Question 18mediummulti select
Read the full VPN explanation →

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is established, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees the tunnel is up. Which two additional diagnostics should the administrator run to isolate the issue?

Question 19hardmulti select
Read the full VPN explanation →

A company wants to implement SSL VPN split tunneling to allow remote users to access both internal resources and the internet directly. Which three configurations are required on the FortiGate?

Question 20mediummulti select
Read the full VPN explanation →

An administrator is configuring Active Directory polling for FSSO. Which two components must be set up correctly for FSSO to work?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Authentication and VPN sessions

Start a Authentication and VPN only practice session

Every question in these sessions is drawn from the Authentication and VPN domain — nothing else.

Related practice questions

Related NSE4 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE4 exam test about Authentication and VPN?
Be able to configure and troubleshoot IPsec and SSL VPN authentication on FortiGate. The single most important skill is using diagnose vpn ike config, diagnose vpn tunnel list, and IKE debug to determine why a tunnel or user traffic fails.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Authentication and VPN questions in a focused session?
Yes — the session launcher on this page draws every question from the Authentication and VPN domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE4 topics?
Use the topic links above to move to related areas, or go back to the NSE4 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE4 exam covers. They are not copied from any real exam or dump site.