FCSS_LED_AR-7.6 · Question #36
You want to configure Syslog-based single sign-on (SSO) on FortiAuthenticator to enhance user authentication across your network. You have to ensure that the system correctly extracts the user…
The correct answer is A. Specify the devices that will send syslog messages to FortiAuthenticator. B. Configure parsing rules to extract the relevant information from syslog messages. Configuring Syslog SSO on FortiAuthenticator requires two foundational steps: telling the system which devices to trust as syslog sources (A) and defining how to interpret the messages those devices send (B). Without specifying trusted syslog senders, FortiAuthenticator cannot…
Question
You want to configure Syslog-based single sign-on (SSO) on FortiAuthenticator to enhance user authentication across your network. You have to ensure that the system correctly extracts the user information from syslog messages and links it to the correct authentication events. Which two steps must you perform to successfully configure Syslog SSO on FortiAuthenticator? (Choose two.)
Options
- ASpecify the devices that will send syslog messages to FortiAuthenticator.
- BConfigure parsing rules to extract the relevant information from syslog messages.
- CConfigure the syslog messages that FortiAuthenticator sends to authentication devices.
- DSet up user authentication policies in FortiAuthenticator.
- EEnable syslog forwarding on source devices.
How the community answered
(44 responses)- A73% (32)
- C14% (6)
- D5% (2)
- E9% (4)
Explanation
Configuring Syslog SSO on FortiAuthenticator requires two foundational steps: telling the system which devices to trust as syslog sources (A) and defining how to interpret the messages those devices send (B). Without specifying trusted syslog senders, FortiAuthenticator cannot securely accept or process incoming messages; without parsing rules, it cannot extract usernames, IPs, or login events from the raw syslog text to map them to authentication events.
Why the distractors are wrong:
- C reverses the direction - Syslog SSO is about FortiAuthenticator receiving syslogs from other devices, not sending them.
- D is a general FortiAuthenticator concept, but local authentication policies are separate from SSO configuration and not a required step for Syslog SSO specifically.
- E sounds plausible, but enabling syslog forwarding is something done on the source device's own config - FortiAuthenticator itself doesn't perform this step as part of its own SSO setup.
Memory tip: Think of it as a two-sided handshake - FortiAuthenticator must know WHO is allowed to send logs (A = allowlist of senders) and HOW to read what they send (B = parsing rules). Everything else is either on the wrong side of the connection or outside the SSO-specific workflow.
Topics
Community Discussion
No community discussion yet for this question.