FCP_FAZ_AN-7.6 · Question #49
Which two external servers can you configure to validate administrator logins? (Choose two.)
The correct answer is A. RADIUS D. LDAP. RADIUS and LDAP are both industry-standard external authentication protocols supported by FortiGate (and most enterprise network devices) for validating administrator credentials against a centralized identity store - RADIUS is commonly used with dial-in and VPN authentication…
Question
Which two external servers can you configure to validate administrator logins? (Choose two.)
Options
- ARADIUS
- BOnly locally by FortiAnalyzer
- CSyslog
- DLDAP
How the community answered
(43 responses)- A88% (38)
- B7% (3)
- C5% (2)
Explanation
RADIUS and LDAP are both industry-standard external authentication protocols supported by FortiGate (and most enterprise network devices) for validating administrator credentials against a centralized identity store - RADIUS is commonly used with dial-in and VPN authentication infrastructure, while LDAP integrates directly with directory services like Microsoft Active Directory.
Why the distractors are wrong:
- B (Only locally by FortiAnalyzer) is wrong on two counts: FortiAnalyzer is a log management/analytics appliance, not an authentication server, and the question specifically asks about external servers.
- C (Syslog) is a logging/event-forwarding protocol - it receives log data from devices but has no authentication capability whatsoever.
Memory tip: Think "RL = Remote Logins" - RADIUS and LDAP are the two protocols that let an external server handle your admin authentication. If a protocol's job is logging (Syslog) or analyzing (FortiAnalyzer), it can't authenticate.
Topics
Community Discussion
No community discussion yet for this question.