nerdexam
Fortinet

NSE4 · Question #112

When firewall policy authentication is enabled, only traffic on supported protocols will trigger an authentication challenge. Select all supported protocols from the following:

The correct answer is C. HTTP D. FTP. Firewall policy authentication challenges are typically triggered for common web and file transfer protocols like HTTP and FTP.

Submitted by neha2k· Apr 18, 2026Firewall Policies and Authentication

Question

When firewall policy authentication is enabled, only traffic on supported protocols will trigger an authentication challenge. Select all supported protocols from the following:

Options

  • ASMTP
  • BSSH
  • CHTTP
  • DFTP
  • ESCP

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (30)

Why each option

Firewall policy authentication challenges are typically triggered for common web and file transfer protocols like HTTP and FTP.

ASMTP

SMTP (email) traffic is generally not subjected to direct firewall policy authentication challenges, as it typically operates between servers or from clients through email clients.

BSSH

SSH (secure shell) is usually authenticated by the SSH server itself, not by an intermediate firewall policy directly challenging the user connection.

CHTTPCorrect

HTTP is a widely supported protocol for firewall policy authentication, often used with captive portals or explicit web proxy authentication.

DFTPCorrect

FTP is another protocol that can trigger authentication challenges in firewall policies, especially for file transfer access control.

ESCP

SCP (secure copy protocol) is a file transfer protocol over SSH and is authenticated by the SSH server, not typically by a firewall policy challenge.

Concept tested: Firewall authentication supported protocols

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/127117/authentication-firewall-policies

Topics

#Firewall policy#User authentication#Supported protocols#FortiGate features

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice