FCSS_EFW_AD-7.6 · Question #27
Refer to the exhibits. The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown. When prompted to sign in with…
The correct answer is C. The user accesses the downstream FortiGate with super_admin_readonly privileges. From the Root FortiGate - System Administrator Configuration exhibit: The AdminSSO account has the super_admin_readonly role. From the Downstream FortiGate - Security Fabric Settings exhibit: The Security Fabric role is set to Join Existing Fabric, meaning it will authenticate…
Question
Refer to the exhibits. The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown. When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials. What is the next status for the user?
Exhibits
Options
- AThe user is prompted to create an SSO administrator account for AdminSSO.
- BThe user receives an authentication failure message.
- CThe user accesses the downstream FortiGate with super_admin_readonly privileges.
- DThe user accesses the downstream FortiGate with super_admin privileges.
How the community answered
(43 responses)- A7% (3)
- B2% (1)
- C77% (33)
- D14% (6)
Explanation
From the Root FortiGate - System Administrator Configuration exhibit: The AdminSSO account has the super_admin_readonly role. From the Downstream FortiGate - Security Fabric Settings exhibit: The Security Fabric role is set to Join Existing Fabric, meaning it will authenticate with the root SAML Single Sign-On (SSO) is enabled, and the default admin profile is set to super_admin_readonly. When the AdminSSO user logs into the downstream FortiGate using SSO, the authentication request is sent to the root FortiGate, where AdminSSO has super_admin_readonly permissions. Since the downstream FortiGate inherits this permission through the Security Fabric configuration, the user will be granted super_admin_readonly access.
Topics
Community Discussion
No community discussion yet for this question.

