Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator configures SAML SSO with FortiGate as the Service Provider (SP) and an external IdP. Users report that they are prompted for credentials repeatedly without successful authentication. What is the most likely cause?

⚠ Common exam trap

NSE7 often tests the misconception that attribute mapping or firewall policies cause SSO loops, when the most common root cause is a missing or untrusted IdP signing certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IdP certificate is not imported or trusted on the FortiGate

When FortiGate acts as SAML SP, it must validate the IdP's signed SAML assertions using the IdP's signing certificate. If the IdP certificate is not imported and trusted on the FortiGate, signature validation fails, and authentication cannot complete — users are repeatedly redirected to the IdP and back without a successful login. This is the most common cause of SAML SSO loops in FortiGate deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SAML attribute mapping is incorrect

    Why it's wrong here

    Incorrect attribute mapping leaves the FortiGate unable to match the IdP's assertion to a local user or group, so authentication never completes and the login loop repeats. It is tempting because mapping errors do break SSO, but the stem's repeated credential prompts point to assertion or clock validation failing first.

  • ✗

    The FortiGate's clock is synchronized via NTP

    Why it's wrong here

    NTP synchronisation is required for SAML assertions to validate, so a synchronised clock is expected, not a fault. Repeated credential prompts point to a signature or certificate mismatch between the FortiGate SP and the IdP, or an incorrect entity ID. NTP matters when assertion timestamps fall outside the allowed clock skew window.

  • ✗

    The firewall policy does not allow SAML traffic

    Why it's wrong here

    SAML authentication exchanges occur between the user's browser and the IdP, then post back to FortiGate; the firewall policy governs only the resulting authenticated session, not the SSO handshake itself. It is tempting because firewall policies do control traffic flows, but here the repeated prompts stem from a SAML configuration mismatch, such as an incorrect entity ID or certificate.

  • ✓

    The IdP certificate is not imported or trusted on the FortiGate

    Why this is correct

    SAML assertions are signed by the IdP, so the FortiGate must hold and trust the IdP signing certificate to validate them. Without that certificate imported, signature validation fails, authentication never completes, and users are repeatedly redirected to the IdP login.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.