nerdexam
Fortinet

NSE4 · Question #108

When firewall policy authentication is enabled, which protocols can trigger an authentication challenge? (Choose two.)

The correct answer is C. HTTP D. FTP. When firewall policy authentication is enabled, HTTP and FTP are common protocols that can trigger an authentication challenge.

Submitted by anjalisingh· Apr 18, 2026Firewall Policies and Authentication

Question

When firewall policy authentication is enabled, which protocols can trigger an authentication challenge? (Choose two.)

Options

  • ASMTP
  • BPOP3
  • CHTTP
  • DFTP

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    88% (23)

Why each option

When firewall policy authentication is enabled, HTTP and FTP are common protocols that can trigger an authentication challenge.

ASMTP

SMTP (email sending) is typically a server-to-server or client-to-server protocol that does not inherently support user-interactive authentication challenges suitable for firewall policies.

BPOP3

POP3 (email receiving) is also typically a client-to-server protocol, and while it involves user credentials, it's not a protocol that commonly triggers a firewall-level interactive authentication challenge.

CHTTPCorrect

HTTP is a primary protocol used for web-based authentication, where the FortiGate can redirect users to a captive portal to perform authentication.

DFTPCorrect

FTP traffic can also be intercepted by the FortiGate to trigger an authentication challenge, often via a proxy-based approach, requiring users to authenticate before accessing FTP resources.

Concept tested: FortiGate firewall policy authentication trigger protocols

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/700813/firewall-policies

Topics

#Firewall authentication#Policy enforcement#Application protocols#User authentication

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice