NSE4 · Question #251
Which of the following cannot be used in conjunction with the endpoint compliance check?
The correct answer is A. HTTP Challenge Redirect to a Secure Channel (HTTPS) in the Authentication Settings. Endpoint compliance checks cannot be used with HTTP Challenge Redirect to HTTPS as these features represent conflicting methods for initial client handling.
Question
Which of the following cannot be used in conjunction with the endpoint compliance check?
Options
- AHTTP Challenge Redirect to a Secure Channel (HTTPS) in the Authentication Settings.
- BAny form of firewall policy authentication.
- CWAN optimization.
- DTraffic shaping.
How the community answered
(34 responses)- A79% (27)
- B6% (2)
- C12% (4)
- D3% (1)
Why each option
Endpoint compliance checks cannot be used with HTTP Challenge Redirect to HTTPS as these features represent conflicting methods for initial client handling.
HTTP Challenge Redirect forces unauthenticated users to an HTTPS portal for authentication, which is an initial connection control mechanism. Endpoint compliance checks, designed to assess client posture before granting access, typically require a stable connection state and can be disrupted or made incompatible by this type of redirection, preventing proper functionality.
Endpoint compliance checks are often integrated with firewall policy authentication to grant access based on compliance status, making them compatible.
WAN optimization operates on the traffic stream after authentication and compliance, and thus can coexist with endpoint compliance.
Traffic shaping applies bandwidth management after the connection is established and authenticated, making it compatible with endpoint compliance checks.
Concept tested: FortiGate endpoint compliance interaction with authentication methods
Topics
Community Discussion
No community discussion yet for this question.