Courseiva
Advanced VPN and Zero TrustmediumMultiple ChoiceObjective-mapped

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?

⚠ Common exam trap

Test-takers frequently confuse SAML's asymmetric signing requirement with symmetric pre-shared keys used in VPNs, or assume that external user synchronization is mandatory, when in fact local users or other identity stores suffice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A certificate for signing SAML assertions

When FortiGate acts as a SAML IdP, it must sign SAML assertions to prove their authenticity to the SP. A certificate is required for this signing, as the SP will validate the assertion using the IdP's public key. Without a signing certificate, the SAML response cannot be cryptographically verified, breaking the trust model defined in the SAML 2.0 specification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The SP's metadata must be imported as a firewall address

    Why it's wrong here

    SP metadata is imported into the SAML IdP configuration, not as firewall address.

  • User accounts must be synchronized with an LDAP server

    Why it's wrong here

    User accounts can be local or remote, but synchronization is not required for the IdP role itself.

  • A certificate for signing SAML assertions

    Why this is correct

    The IdP must have a certificate to sign SAML responses. This certificate is trusted by the SP.

  • A pre-shared key between FortiGate and the SP

    Why it's wrong here

    SAML uses certificates, not pre-shared keys.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.