nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #25

You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied. What should the administrator check first?

The correct answer is C. The FortiGate FSSO active users list for user's IP address. Checking the active users list verifies if FortiGate correctly associates the user with their IP address, ensuring proper policy enforcement for internet access.

Submitted by anjalisingh· Apr 18, 2026Firewall policies and authentication

Question

You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied. What should the administrator check first?

Options

  • AWhether the user is assigned to the correct AD group.
  • BThe FortiGate firewall policy settings for SSL decryption.
  • CThe FortiGate FSSO active users list for user's IP address.
  • DThe windows event viewer for failed login attempts.

How the community answered

(37 responses)
  • A
    11% (4)
  • B
    14% (5)
  • C
    70% (26)
  • D
    5% (2)

Explanation

Checking the active users list verifies if FortiGate correctly associates the user with their IP address, ensuring proper policy enforcement for internet access.

Topics

#FSSO#User authentication#Troubleshooting#Firewall policies

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice