Courseiva
Enterprise Firewall and VDOMsmediumMatchingObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

Match each FortiGate authentication method to its protocol.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Lightweight Directory Access Protocol

Remote Authentication Dial-In User Service

Terminal Access Controller Access-Control System Plus

Fortinet Single Sign-On

Public Key Infrastructure

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

LDAP: Lightweight Directory Access Protocol

FortiGate supports multiple authentication methods, each using a specific protocol. LDAP uses LDAP, RADIUS uses RADIUS, TACACS+ uses TACACS+, and SAML uses SAML. Common confusions include swapping LDAP and RADIUS definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • LDAP: Lightweight Directory Access Protocol

    Why this is correct

    LDAP uses the Lightweight Directory Access Protocol for authentication and directory lookups.

  • RADIUS: Remote Authentication Dial-In User Service

    Why this is correct

    RADIUS uses the Remote Authentication Dial-In User Service protocol for AAA services.

  • TACACS+: Terminal Access Controller Access-Control System Plus

    Why this is correct

    TACACS+ uses the Terminal Access Controller Access-Control System Plus protocol, separating authentication, authorization, and accounting.

  • SAML: Security Assertion Markup Language

    Why this is correct

    SAML uses the Security Assertion Markup Language for single sign-on authentication.

  • LDAP: Remote Authentication Dial-In User Service

    Why it's wrong here

    Incorrect — this describes RADIUS, not LDAP. LDAP uses the Lightweight Directory Access Protocol.

  • RADIUS: Lightweight Directory Access Protocol

    Why it's wrong here

    Incorrect — this describes LDAP, not RADIUS. RADIUS uses the Remote Authentication Dial-In User Service.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.