NSE4 Authentication and VPN Practice Question
Which authentication method allows a FortiGate to transparently authenticate users based on their Active Directory login events without prompting for credentials?
⚠ Common exam trap
Candidates often confuse LDAP or RADIUS with SSO capabilities, but neither provides transparent authentication without credential prompts—only FSSO captures existing Windows logon events to achieve true single sign-on.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FSSO (Fortinet Single Sign-On)
Fortinet Single Sign-On (FSSO) allows FortiGate to transparently authenticate users by collecting login events from Active Directory domain controllers. It uses the NetAPI or a polling mechanism to capture user logon events without requiring any user interaction or credential prompts, enabling seamless identity-based policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS authentication
Why it's wrong here
RADIUS authentication is typically a network access protocol used for VPN, 802.1X, or dial-up scenarios. It generally requires the user to actively present credentials (password, token, or certificate) at the time of authentication, and though it can support SSO features like EAP-PEAP, it does not passively consume Windows Active Directory logon events. The FortiGate would need to prompt the user or relay an existing authentication from another device, so it is not transparent based on AD activity.
- ✓
FSSO (Fortinet Single Sign-On)
Why this is correct
FSSO (Fortinet Single Sign-On) is the correct method because it actively monitors a domain controller for user logon events, either via a Collector Agent or by polling the Windows Security Log. When a user logs into the Windows domain, FSSO fetches the username and the workstation IP/MAC and sends this information to the FortiGate, which then automatically maps the user to the web filter, firewall policy, or application control profiles. The user is never prompted for authentication because the AD authentication is captured transparently, making FSSO the only listed option that meets the requirement.
- ✗
Local database authentication
Why it's wrong here
Local database authentication relies on usernames and password hashes stored directly on the FortiGate's own user database. When a user attempts to access a protected resource, the FortiGate presents a login page or prompts for credentials, and the user must manually enter their username and password to pass through. This database is static and has no connection to Active Directory events, so it cannot detect or use existing Windows domain logons, meaning it is inherently non-transparent and requires active user intervention.
- ✗
LDAP authentication
Why it's wrong here
LDAP authentication uses a directory server such as Active Directory or OpenLDAP as the backend for validating credentials, but it still requires the user to supply a username and password each time a new session or access attempt begins. The FortiGate performs a bind request against the LDAP server using those supplied credentials, so the user must interact with a login prompt. It does not monitor domain logon events or correlate successful AD logins to network sessions, so it lacks the transparent, event-driven behavior that the question asks for.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.