nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #27

Refer to the exhibits. The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown. When prompted to sign in with…

The correct answer is C. The user accesses the downstream FortiGate with super_admin_readonly privileges. From the Root FortiGate - System Administrator Configuration exhibit: The AdminSSO account has the super_admin_readonly role. From the Downstream FortiGate - Security Fabric Settings exhibit: The Security Fabric role is set to Join Existing Fabric, meaning it will authenticate…

Infrastructure and Integration

Question

Refer to the exhibits. The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown. When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials. What is the next status for the user?

Exhibits

FCSS_EFW_AD-7.4 question #27 exhibit 1
FCSS_EFW_AD-7.4 question #27 exhibit 2

Options

  • AThe user is prompted to create an SSO administrator account for AdminSSO.
  • BThe user receives an authentication failure message.
  • CThe user accesses the downstream FortiGate with super_admin_readonly privileges.
  • DThe user accesses the downstream FortiGate with super_admin privileges.

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    13% (6)
  • C
    80% (37)
  • D
    2% (1)

Explanation

From the Root FortiGate - System Administrator Configuration exhibit: The AdminSSO account has the super_admin_readonly role. From the Downstream FortiGate - Security Fabric Settings exhibit: The Security Fabric role is set to Join Existing Fabric, meaning it will authenticate with the root SAML Single Sign-On (SSO) is enabled, and the default admin profile is set to super_admin_readonly. When the AdminSSO user logs into the downstream FortiGate using SSO, the authentication request is sent to the root FortiGate, where AdminSSO has super_admin_readonly permissions. Since the downstream FortiGate inherits this permission through the Security Fabric configuration, the user will be granted super_admin_readonly access.

Topics

#Security Fabric#SSO#admin privileges#downstream FortiGate

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice