NSE4 · Question #250
Which of the following statements is correct about how the FortiGate unit verifies username and password during user authentication?
The correct answer is B. An administrator can define a local account for which the password must be verified by querying a. FortiGate offers flexible authentication, allowing administrators to configure a local user account whose password verification is delegated to an external authentication server, blending local username management with remote password validation.
Question
Which of the following statements is correct about how the FortiGate unit verifies username and password during user authentication?
Options
- AIf a remote server is included in a user group, it will be checked before local accounts.
- BAn administrator can define a local account for which the password must be verified by querying a
- CIf authentication fails with a local password, the FortiGate unit will query the authentication server
- DThe FortiGate unit will only attempt to authenticate against Active Directory if Fortinet Server
How the community answered
(37 responses)- B92% (34)
- C5% (2)
- D3% (1)
Why each option
FortiGate offers flexible authentication, allowing administrators to configure a local user account whose password verification is delegated to an external authentication server, blending local username management with remote password validation.
The order of authentication checks (local vs. remote) is configurable within user groups or authentication rules and is not a fixed behavior where remote servers are always checked first.
FortiGate supports a hybrid authentication method where a local user account can be created, but its password authentication is specifically configured to be validated against an external authentication server, such as RADIUS or LDAP, allowing centralized password management for local accounts.
If authentication fails with a local password for a locally configured user, the FortiGate unit typically terminates that specific authentication attempt; it does not automatically fall back to querying a remote server unless explicitly configured within an authentication scheme.
FortiGate units can authenticate directly against Active Directory using standard LDAP or RADIUS protocols without requiring specific Fortinet Server authentication software.
Concept tested: FortiGate user authentication methods and hybrid accounts
Source: https://docs.fortinet.com/document/fortigate/7.0.0/administration-guide/339414/users-and-authentication
Topics
Community Discussion
No community discussion yet for this question.