nerdexam
Fortinet

FCP_FAZ_AN-7.6 · Question #49

Which two external servers can you configure to validate administrator logins? (Choose two.)

The correct answer is A. RADIUS D. LDAP. RADIUS and LDAP are both industry-standard external authentication protocols supported by FortiGate (and most enterprise network devices) for validating administrator credentials against a centralized identity store - RADIUS is commonly used with dial-in and VPN authentication…

Logging and Monitoring

Question

Which two external servers can you configure to validate administrator logins? (Choose two.)

Options

  • ARADIUS
  • BOnly locally by FortiAnalyzer
  • CSyslog
  • DLDAP

How the community answered

(43 responses)
  • A
    88% (38)
  • B
    7% (3)
  • C
    5% (2)

Explanation

RADIUS and LDAP are both industry-standard external authentication protocols supported by FortiGate (and most enterprise network devices) for validating administrator credentials against a centralized identity store - RADIUS is commonly used with dial-in and VPN authentication infrastructure, while LDAP integrates directly with directory services like Microsoft Active Directory.

Why the distractors are wrong:

  • B (Only locally by FortiAnalyzer) is wrong on two counts: FortiAnalyzer is a log management/analytics appliance, not an authentication server, and the question specifically asks about external servers.
  • C (Syslog) is a logging/event-forwarding protocol - it receives log data from devices but has no authentication capability whatsoever.

Memory tip: Think "RL = Remote Logins" - RADIUS and LDAP are the two protocols that let an external server handle your admin authentication. If a protocol's job is logging (Syslog) or analyzing (FortiAnalyzer), it can't authenticate.

Topics

#RADIUS#LDAP#administrator authentication#external servers

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AN-7.6 Practice