Courseiva
Troubleshooting and DiagnosticsmediumMultiple ChoiceObjective-mapped

NSE7 FIPS mode Practice Question

A FortiGate admin runs 'diagnose debug application authd -1' but sees no output for LDAP authentication attempts. What is the MOST likely reason?

⚠ Common exam trap

Candidates often assume that additional debug flow is needed when 'diagnose debug application authd' shows no output, but the real common reason is that the FortiGate is in FIPS mode, which restricts debug commands. Alternatively, if the debug command is run after the fact, no historical output is shown.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The FortiGate is in FIPS mode

The 'diagnose debug application authd -1' command enables verbose debug logging for the authentication daemon. However, on a FortiGate running in FIPS mode, many debug commands are restricted or produce no output to comply with security requirements. This is the most likely reason for observing no LDAP authentication debug output. Other possible reasons include running the command after authentication attempts have completed, but FIPS mode is a definitive system-level constraint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The LDAP server is unreachable

    Why it's wrong here

    If the LDAP server is unreachable, authd would typically log connection failures in the debug output. This would not cause a complete absence of output.

  • The FortiGate is in FIPS mode

    Why this is correct

    In FIPS mode, FortiGate disables many debug capabilities to maintain compliance, so authd debug output will not be displayed even if authentication attempts are occurring. This is the most likely reason.

  • The LDAP server timed out

    Why it's wrong here

    An LDAP server timeout would still generate debug logs from authd indicating the timeout event. It would not cause zero output.

  • Debug flow is not enabled

    Why it's wrong here

    Enabling debug flow is not required for authd to log authentication attempts. The 'diagnose debug application authd' command alone is sufficient to capture authd logs, provided debug is active and the system is not in FIPS mode.

About these practice questions

One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.