nerdexam
Fortinet

NSE4 · Question #232

With FSSO, a domain user could authenticate either against the domain controller running the Collector Agent and Domain Controller Agent, or a domain controller running only the Domain Controller…

The correct answer is A. The login event is sent to the Collector Agent. C. The Collector Agent performs the DNS lookup for the authenticated client's IP address. When a user authenticates with a Secondary Domain Controller running only the FSSO Domain Controller Agent, the login event is sent to the Collector Agent, which then performs DNS lookup for the client's IP.

Submitted by tom_us· Apr 18, 2026Firewall and Authentication

Question

With FSSO, a domain user could authenticate either against the domain controller running the Collector Agent and Domain Controller Agent, or a domain controller running only the Domain Controller Agent. If you attempt to authenticate with the Secondary Domain Controller running only the Domain Controller Agent, which of the following statements are correct? (Select all that apply.)

Options

  • AThe login event is sent to the Collector Agent.
  • BThe FortiGate unit receives the user information from the Domain Controller Agent of the
  • CThe Collector Agent performs the DNS lookup for the authenticated client's IP address.
  • DThe user cannot be authenticated with the FortiGate device in this manner because each Domain

How the community answered

(28 responses)
  • A
    82% (23)
  • B
    7% (2)
  • D
    11% (3)

Why each option

When a user authenticates with a Secondary Domain Controller running only the FSSO Domain Controller Agent, the login event is sent to the Collector Agent, which then performs DNS lookup for the client's IP.

AThe login event is sent to the Collector Agent.Correct

The Domain Controller Agent's primary function is to detect user login events on the DC it's installed on and forward these events to the central FSSO Collector Agent.

BThe FortiGate unit receives the user information from the Domain Controller Agent of the

The FortiGate unit communicates with the *Collector Agent* to retrieve user-to-IP mappings, not directly with individual Domain Controller Agents.

CThe Collector Agent performs the DNS lookup for the authenticated client's IP address.Correct

Upon receiving a login event (user and IP address) from a Domain Controller Agent, the FSSO Collector Agent typically performs a reverse DNS lookup for the authenticated client's IP address to retrieve its hostname, which is then used in user-IP mapping tables.

DThe user cannot be authenticated with the FortiGate device in this manner because each Domain

The FSSO architecture is designed for this scenario, allowing authentication through a Domain Controller Agent forwarding events to a central Collector Agent, making the statement incorrect.

Concept tested: FortiGate Single Sign-On (FSSO) architecture and flow

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/572175/fsso-architecture

Topics

#FSSO#Authentication Flow#Collector Agent#Domain Controller Agent

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice