Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Fortinet Single Sign On Deployment And Troubleshooting Practice Test
This Fortinet NSE4_FGT_AD-7.6 practice test focuses on fortinet single sign on deployment and troubleshooting through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.
Question 1
A change review at Apex Retail identifies one requirement: collect Windows domain logon events with the recommended agent-based architecture. Which FortiGate action best satisfies it? The team wants the smallest change that directly addresses the requirement.
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: A
Explanation
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This directly satisfies the stated requirement.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
Learning point: For this FortiOS 7.6 scenario, install a DC agent on each monitored domain controller and send those events to an FSSO collector agent. DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling.
Question 2
While troubleshooting at Proseware Media, the network operations engineer needs to consolidate domain logon events and provide user-to-IP information to FortiGate. What is the best next step? The choice should follow normal FortiOS administration practice.
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
Correct answer: A
Explanation
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This directly satisfies the stated requirement.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
Learning point: For this FortiOS 7.6 scenario, use the FSSO collector agent to receive login data, perform group processing, and update FortiGate. The collector agent aggregates authentication events and distributes identity information to FortiGate.
Question 3
City Power & Light is standardizing its FortiGate 7.6 operations. Which approach should it use to ensure FortiGate receives only identities from groups used by firewall policy? The solution must preserve the existing production design where possible.
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
Correct answer: A
Explanation
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This directly satisfies the stated requirement.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
Learning point: For this FortiOS 7.6 scenario, configure appropriate FSSO group filters or monitored groups between the collector and FortiGate. Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements.
Question 4
A production ticket for Margie Travel states that administrators must troubleshoot a user who logged on to the domain but never appears on FortiGate. Which choice is correct? The change is being made during a controlled production window.
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: A
Explanation
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This directly satisfies the stated requirement.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
Learning point: For this FortiOS 7.6 scenario, trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter. FSSO troubleshooting should follow the event path to identify where identity propagation failed.
Question 5
The security team at Bellows College wants to investigate an incorrect user identity remaining on a shared workstation address. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: E
Explanation
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, check stale login records, logoff detection, workstation checks, address reuse, and collector status. Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity.
Question 6
An incident at Adventure Works requires the network operations engineer to allow domain users to reach an internal service without another browser login prompt. What should be done first? No unrelated security controls should be changed.
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
Correct answer: D
Explanation
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- FSSO enables identity-aware access based on existing domain authentication. This directly satisfies the stated requirement.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
Learning point: For this FortiOS 7.6 scenario, use FSSO identity in the firewall policy when the domain login is a trusted authentication source. FSSO enables identity-aware access based on existing domain authentication.
Question 7
For a FortiGate 7.6 deployment at Fourth Coffee, which option correctly addresses the need to choose between DC-agent mode and collector polling when login-event reliability and scale are important? The administrator wants a configuration that is easy to audit later.
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
Correct answer: D
Explanation
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This directly satisfies the stated requirement.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
Learning point: For this FortiOS 7.6 scenario, prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding. DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling.
Question 8
Consolidated Messenger has validated routing and basic reachability. The remaining requirement is to verify FSSO is connected before troubleshooting a firewall rule. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
Correct answer: B
Explanation
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This directly satisfies the stated requirement.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
Learning point: For this FortiOS 7.6 scenario, confirm the FSSO collector connection and active user entries on FortiGate first. If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order.
Question 9
At VanArsdel, a FortiGate administrator is handling a FortiGate 7.6 change. The requirement is to collect Windows domain logon events with the recommended agent-based architecture. What should the administrator do? The team wants the smallest change that directly addresses the requirement.
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: A
Explanation
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This directly satisfies the stated requirement.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
Learning point: For this FortiOS 7.6 scenario, install a DC agent on each monitored domain controller and send those events to an FSSO collector agent. DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling.
Question 10
During a maintenance window at Northwind Health, the team must consolidate domain logon events and provide user-to-IP information to FortiGate. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: A
Explanation
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This directly satisfies the stated requirement.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
Learning point: For this FortiOS 7.6 scenario, use the FSSO collector agent to receive login data, perform group processing, and update FortiGate. The collector agent aggregates authentication events and distributes identity information to FortiGate.
Question 11
A change review at Blue Yonder Airlines identifies one requirement: ensure FortiGate receives only identities from groups used by firewall policy. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Confirm the FSSO collector connection and active user entries on FortiGate first
Correct answer: D
Explanation
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This directly satisfies the stated requirement.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
Learning point: For this FortiOS 7.6 scenario, configure appropriate FSSO group filters or monitored groups between the collector and FortiGate. Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements.
Question 12
While troubleshooting at Trey Research, the network operations engineer needs to troubleshoot a user who logged on to the domain but never appears on FortiGate. What is the best next step? The change is being made during a controlled production window.
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: D
Explanation
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This directly satisfies the stated requirement.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
Learning point: For this FortiOS 7.6 scenario, trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter. FSSO troubleshooting should follow the event path to identify where identity propagation failed.
Question 13
Nod Publishers is standardizing its FortiGate 7.6 operations. Which approach should it use to investigate an incorrect user identity remaining on a shared workstation address? The team will validate the result immediately after the change.
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Confirm the FSSO collector connection and active user entries on FortiGate first
Correct answer: D
Explanation
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This directly satisfies the stated requirement.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate an incorrect user identity remaining on a shared workstation address.
Learning point: For this FortiOS 7.6 scenario, check stale login records, logoff detection, workstation checks, address reuse, and collector status. Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity.
Question 14
A production ticket for Contoso Finance states that administrators must allow domain users to reach an internal service without another browser login prompt. Which choice is correct? No unrelated security controls should be changed.
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
Correct answer: E
Explanation
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow domain users to reach an internal service without another browser login prompt.
- FSSO enables identity-aware access based on existing domain authentication. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use FSSO identity in the firewall policy when the domain login is a trusted authentication source. FSSO enables identity-aware access based on existing domain authentication.
Question 15
The security team at Litware Logistics wants to choose between DC-agent mode and collector polling when login-event reliability and scale are important. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
Correct answer: B
Explanation
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This directly satisfies the stated requirement.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to choose between DC-agent mode and collector polling when login-event reliability and scale are important.
Learning point: For this FortiOS 7.6 scenario, prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding. DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling.
Question 16
An incident at Wide World Importers requires the network operations engineer to verify FSSO is connected before troubleshooting a firewall rule. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Confirm the FSSO collector connection and active user entries on FortiGate first
Correct answer: E
Explanation
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify FSSO is connected before troubleshooting a firewall rule.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, confirm the FSSO collector connection and active user entries on FortiGate first. If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order.
Question 17
For a FortiGate 7.6 deployment at Graphic Design Institute, which option correctly addresses the need to collect Windows domain logon events with the recommended agent-based architecture? The team wants the smallest change that directly addresses the requirement.
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
Correct answer: D
Explanation
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This directly satisfies the stated requirement.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to collect Windows domain logon events with the recommended agent-based architecture.
Learning point: For this FortiOS 7.6 scenario, install a DC agent on each monitored domain controller and send those events to an FSSO collector agent. DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling.
Question 18
Lamna Healthcare has validated routing and basic reachability. The remaining requirement is to consolidate domain logon events and provide user-to-IP information to FortiGate. Which action should the team take? The choice should follow normal FortiOS administration practice.
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
- Confirm the FSSO collector connection and active user entries on FortiGate first
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
Correct answer: E
Explanation
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- If the identity source is disconnected, user-based policy cannot match as intended regardless of rule order. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to consolidate domain logon events and provide user-to-IP information to FortiGate.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use the FSSO collector agent to receive login data, perform group processing, and update FortiGate. The collector agent aggregates authentication events and distributes identity information to FortiGate.
Question 19
At Tailspin Toys, a FortiGate administrator is handling a FortiGate 7.6 change. The requirement is to ensure FortiGate receives only identities from groups used by firewall policy. What should the administrator do? The solution must preserve the existing production design where possible.
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Install a DC agent on each monitored domain controller and send those events to an FSSO collector agent
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Configure appropriate FSSO group filters or monitored groups between the collector and FortiGate
Correct answer: E
Explanation
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- DC agent mode forwards logon events from domain controllers to the collector, reducing reliance on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure FortiGate receives only identities from groups used by firewall policy.
- Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, configure appropriate FSSO group filters or monitored groups between the collector and FortiGate. Group filtering reduces unnecessary identity records and aligns FSSO data with policy requirements.
Question 20
During a maintenance window at Humongous Insurance, the team must troubleshoot a user who logged on to the domain but never appears on FortiGate. Which action is the most appropriate? The change is being made during a controlled production window.
- Use the FSSO collector agent to receive login data, perform group processing, and update FortiGate
- Prefer DC-agent mode when agents can be deployed to the domain controllers and operational requirements favor event forwarding
- Check stale login records, logoff detection, workstation checks, address reuse, and collector status
- Use FSSO identity in the firewall policy when the domain login is a trusted authentication source
- Trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter
Correct answer: E
Explanation
- The collector agent aggregates authentication events and distributes identity information to FortiGate. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- DC-agent mode directly captures and forwards login events instead of relying solely on periodic polling. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- Stale or reassigned IP-to-user mappings can cause policy to associate traffic with the wrong identity. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- FSSO enables identity-aware access based on existing domain authentication. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a user who logged on to the domain but never appears on FortiGate.
- FSSO troubleshooting should follow the event path to identify where identity propagation failed. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, trace the login from the domain controller to the collector agent and then verify the collector-to-FortiGate connection and group filter. FSSO troubleshooting should follow the event path to identify where identity propagation failed.