nerdexam
Fortinet

NSE4 · Question #173

An administrator has configured a FortiGate unit so that end users must authenticate against the firewall using digital certificates before browsing the Internet. What must the user have for a success

The correct answer is B. A digital certificate issued by any CA server. E. Membership in a firewall user group.. For successful digital certificate authentication on a FortiGate, a user must possess a digital certificate from any trusted Certificate Authority and belong to a configured firewall user group.

Submitted by yuriko_h· Apr 18, 2026Firewall Policies and Authentication

Question

An administrator has configured a FortiGate unit so that end users must authenticate against the firewall using digital certificates before browsing the Internet. What must the user have for a successful authentication? (Select all that apply.)

Options

  • AAn entry in a supported LDAP Directory.
  • BA digital certificate issued by any CA server.
  • CA valid username and password.
  • DA digital certificate issued by the FortiGate unit.
  • EMembership in a firewall user group.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    86% (19)
  • C
    9% (2)

Why each option

For successful digital certificate authentication on a FortiGate, a user must possess a digital certificate from any trusted Certificate Authority and belong to a configured firewall user group.

AAn entry in a supported LDAP Directory.

While LDAP can be used to manage user information, it is not a mandatory component for digital certificate authentication itself, as the certificate serves as the primary credential.

BA digital certificate issued by any CA server.Correct

For certificate-based authentication, the FortiGate unit can validate a digital certificate issued by any Certificate Authority (CA) that the FortiGate has been configured to trust.

CA valid username and password.

Digital certificate authentication typically relies on the certificate itself for identity verification, often replacing the need for a separate username and password.

DA digital certificate issued by the FortiGate unit.

Digital certificates for authentication can be issued by any trusted Certificate Authority, not exclusively by the FortiGate unit itself.

EMembership in a firewall user group.Correct

After successful certificate validation, the user must be a member of a configured firewall user group for the FortiGate to apply appropriate security policies and grant access.

Concept tested: FortiGate certificate authentication requirements

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/339458/certificate-authentication

Topics

#Certificate Authentication#PKI#User Groups#FortiGate Authentication

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice