FCSS_NST_SE-7.4 · Question #85
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command. What two conclusions can you draw from the output? (Choose two.)
The correct answer is C. The collector agent cannot verify if the user is still logged in. E. FSSO is using agentless polling mode to detect logon events. The collector agent cannot verify if the user is still logged in. In agentless‑polling mode FSSO only reads Kerberos TGT events (e.g. 4768) from the DC's security log, and there's no corresponding "logoff" event - so it cannot confirm when a user logs FSSO is using agentless…
Question
Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command. What two conclusions can you draw from the output? (Choose two.)
Exhibit
Options
- AFortinet Single Sign-On (FSSO) is using DC Agent mode to detect logon events.
- BFortiGate is frequently polling the workstation, in case the user has logged off.
- CThe collector agent cannot verify if the user is still logged in.
- DFortiGate polled this event through TCP port 8000.
- EFSSO is using agentless polling mode to detect logon events.
How the community answered
(44 responses)- A7% (3)
- B2% (1)
- C80% (35)
- D11% (5)
Explanation
The collector agent cannot verify if the user is still logged in. In agentless‑polling mode FSSO only reads Kerberos TGT events (e.g. 4768) from the DC's security log, and there's no corresponding "logoff" event - so it cannot confirm when a user logs FSSO is using agentless polling mode to detect logon events. The blank workstation= field and the use of event ID 4768 indicate that fssod is polling the domain controller's event log rather than receiving pushed events from a DC or collector agent.
Topics
Community Discussion
No community discussion yet for this question.
