NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator configures SAML SSO with FortiGate as the Service Provider (SP) and an external IdP. Users report that they are prompted for credentials repeatedly without successful authentication. What is the most likely cause?
⚠ Common exam trap
NSE7 often tests the misconception that attribute mapping or firewall policies cause SSO loops, when the most common root cause is a missing or untrusted IdP signing certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IdP certificate is not imported or trusted on the FortiGate
When FortiGate acts as SAML SP, it must validate the IdP's signed SAML assertions using the IdP's signing certificate. If the IdP certificate is not imported and trusted on the FortiGate, signature validation fails, and authentication cannot complete — users are repeatedly redirected to the IdP and back without a successful login. This is the most common cause of SAML SSO loops in FortiGate deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SAML attribute mapping is incorrect
Why it's wrong here
Incorrect attribute mapping leaves the FortiGate unable to match the IdP's assertion to a local user or group, so authentication never completes and the login loop repeats. It is tempting because mapping errors do break SSO, but the stem's repeated credential prompts point to assertion or clock validation failing first.
- ✗
The FortiGate's clock is synchronized via NTP
Why it's wrong here
NTP synchronisation is required for SAML assertions to validate, so a synchronised clock is expected, not a fault. Repeated credential prompts point to a signature or certificate mismatch between the FortiGate SP and the IdP, or an incorrect entity ID. NTP matters when assertion timestamps fall outside the allowed clock skew window.
- ✗
The firewall policy does not allow SAML traffic
Why it's wrong here
SAML authentication exchanges occur between the user's browser and the IdP, then post back to FortiGate; the firewall policy governs only the resulting authenticated session, not the SSO handshake itself. It is tempting because firewall policies do control traffic flows, but here the repeated prompts stem from a SAML configuration mismatch, such as an incorrect entity ID or certificate.
- ✓
The IdP certificate is not imported or trusted on the FortiGate
Why this is correct
SAML assertions are signed by the IdP, so the FortiGate must hold and trust the IdP signing certificate to validate them. Without that certificate imported, signature validation fails, authentication never completes, and users are repeatedly redirected to the IdP login.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.