nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #118

Refer to the exhibit. FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt. What is the most likely…

The correct answer is A. The Service DNS is required in the firewall policy. DNS traffic can be allowed if user has not authenticated yet. Hostname resolution is often required by the application layer protocol (HTTP/HTTPS/FTP/Telnet) that is used to authenticate. DNS service must be explicity listed as a service in the policy.

Submitted by chen.hong· Apr 18, 2026Firewall policies and authentication

Question

Refer to the exhibit. FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt. What is the most likely reason for this situation?

Exhibit

FCP_FGT_AD-7.6 question #118 exhibit

Options

  • AThe Service DNS is required in the firewall policy.
  • BThe user is using an incorrect user name.
  • CNo matching user account exists for this user.
  • DThe Remote-users group is not added to the Destination.

How the community answered

(48 responses)
  • A
    71% (34)
  • B
    8% (4)
  • C
    4% (2)
  • D
    17% (8)

Explanation

DNS traffic can be allowed if user has not authenticated yet. Hostname resolution is often required by the application layer protocol (HTTP/HTTPS/FTP/Telnet) that is used to authenticate. DNS service must be explicity listed as a service in the policy.

Topics

#Firewall Authentication#Firewall Policy#DNS#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice