nerdexam
Fortinet

FCSS_NST_SE-7.6 · Question #85

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command. What two conclusions can you draw from the output? (Choose two.)

The correct answer is C. The collector agent cannot verify if the user is still logged in. E. FSSO is using agentless polling mode to detect logon events. The collector agent cannot verify if the user is still logged in. In agentless‑polling mode FSSO only reads Kerberos TGT events (e.g. 4768) from the DC's security log, and there's no corresponding "logoff" event - so it cannot confirm when a user logs FSSO is using agentless…

Analyze and Troubleshoot FortiGate Operation

Question

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command. What two conclusions can you draw from the output? (Choose two.)

Options

  • AFortinet Single Sign-On (FSSO) is using DC Agent mode to detect logon events.
  • BFortiGate is frequently polling the workstation, in case the user has logged off.
  • CThe collector agent cannot verify if the user is still logged in.
  • DFortiGate polled this event through TCP port 8000.
  • EFSSO is using agentless polling mode to detect logon events.

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    14% (6)
  • C
    53% (23)
  • D
    28% (12)

Explanation

The collector agent cannot verify if the user is still logged in. In agentless‑polling mode FSSO only reads Kerberos TGT events (e.g. 4768) from the DC's security log, and there's no corresponding "logoff" event - so it cannot confirm when a user logs FSSO is using agentless polling mode to detect logon events. The blank workstation= field and the use of event ID 4768 indicate that fssod is polling the domain controller's event log rather than receiving pushed events from a DC or collector agent.

Topics

#FSSO#agentless polling#DC agent mode#real-time debug

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.6 Practice