Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?

⚠ Common exam trap

Test-takers frequently confuse SAML's asymmetric signing requirement with symmetric pre-shared keys used in VPNs, or assume that external user synchronization is mandatory, when in fact local users or other identity stores suffice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A certificate for signing SAML assertions

When FortiGate acts as a SAML IdP, it must sign SAML assertions to prove their authenticity to the SP. A certificate is required for this signing, as the SP will validate the assertion using the IdP's public key. Without a signing certificate, the SAML response cannot be cryptographically verified, breaking the trust model defined in the SAML 2.0 specification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SP's metadata must be imported as a firewall address

    Why it's wrong here

    The SP's metadata is imported as a SAML service provider entry, not a firewall address object, so address objects cannot hold entity IDs, ACS URLs or certificates. Importing metadata as a firewall address is tempting because FortiGate uses address objects widely elsewhere.

  • ✗

    User accounts must be synchronized with an LDAP server

    Why it's wrong here

    FortiGate's SAML IdP authenticates against its local user database or remote LDAP/RADIUS groups, but synchronising accounts with LDAP is not mandatory. LDAP synchronisation is chosen when directory-backed credentials are wanted; local users alone satisfy the IdP requirement.

  • ✓

    A certificate for signing SAML assertions

    Why this is correct

    SAML assertions must be digitally signed so the service provider can verify they genuinely originate from the FortiGate IdP. A signing certificate is therefore mandatory; without it, the SP rejects assertions and SSO fails during trust validation.

  • ✗

    A pre-shared key between FortiGate and the SP

    Why it's wrong here

    SAML IdP configuration relies on certificates and metadata exchange, not a pre-shared key, which belongs to IPsec or similar tunnels. A pre-shared key is selected when building site-to-site VPN authentication, so it cannot satisfy the SP's signed assertion requirement.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.