nerdexam
Fortinet

NSE4 · Question #114

A client can establish a secure connection to a corporate network using SSL VPN in tunnel mode. Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that

The correct answer is A. Split tunneling can be enabled when using tunnel mode SSL VPN. B. Client software is required to be able to use a tunnel mode SSL VPN. C. Users attempting to create a tunnel mode SSL VPN connection must be authenticated by at least D. The source IP address used by the client for the tunnel mode SSL VPN is assigned by the. SSL VPN in tunnel mode requires client software and authentication, supports split tunneling, and assigns an IP address to the client from the FortiGate.

Submitted by femi9· Apr 18, 2026VPN and Routing

Question

A client can establish a secure connection to a corporate network using SSL VPN in tunnel mode. Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that apply.)

Options

  • ASplit tunneling can be enabled when using tunnel mode SSL VPN.
  • BClient software is required to be able to use a tunnel mode SSL VPN.
  • CUsers attempting to create a tunnel mode SSL VPN connection must be authenticated by at least
  • DThe source IP address used by the client for the tunnel mode SSL VPN is assigned by the

How the community answered

(44 responses)
  • A
    100% (44)

Why each option

SSL VPN in tunnel mode requires client software and authentication, supports split tunneling, and assigns an IP address to the client from the FortiGate.

ASplit tunneling can be enabled when using tunnel mode SSL VPN.Correct

Split tunneling can be enabled in tunnel mode SSL VPN to allow only specific network traffic to go through the VPN tunnel, while other traffic uses the local network connection.

BClient software is required to be able to use a tunnel mode SSL VPN.Correct

Tunnel mode SSL VPN typically requires dedicated client software, such as FortiClient, to establish and manage the full network tunnel.

CUsers attempting to create a tunnel mode SSL VPN connection must be authenticated by at leastCorrect

Users attempting to create any VPN connection, including tunnel mode SSL VPN, must be authenticated to ensure only authorized users gain access.

DThe source IP address used by the client for the tunnel mode SSL VPN is assigned by theCorrect

The FortiGate unit assigns a source IP address from a configured SSL VPN IP pool to the client once the tunnel mode SSL VPN connection is established.

Concept tested: SSL VPN tunnel mode features

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/181555/ssl-vpn-modes

Topics

#SSL VPN#Tunnel Mode#Authentication#Split Tunneling

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice