FCP_FGT_AD-7.6 · Question #43
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?
The correct answer is A. The DC agent sends login event data directly to FortiGate. In DC Agent mode, the DC agent installed on the Domain Controller captures the logon events (e.g., Event ID 4624) in real-time. It then pushes this information to the Collector Agent. The Collector Agent, which runs as a service on a dedicated machine, is responsible for…
Question
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?
Options
- AThe DC agent sends login event data directly to FortiGate.
- BThe user logs into the windows domain.
- CThe collector agent forwards login event data to FortiGate.
- DFortiGate determines user identity based on the IP address in the FSSO list.
How the community answered
(33 responses)- A94% (31)
- B3% (1)
- D3% (1)
Explanation
In DC Agent mode, the DC agent installed on the Domain Controller captures the logon events (e.g., Event ID 4624) in real-time. It then pushes this information to the Collector Agent. The Collector Agent, which runs as a service on a dedicated machine, is responsible for consolidating this information and then forwarding it to the FortiGate firewall. The FortiGate receives this data and uses the user's IP address to apply appropriate security policies.
Topics
Community Discussion
No community discussion yet for this question.