nerdexam
Fortinet

NSE4 · Question #296

Review the exhibit of an explicit proxy policy configuration. If there is a proxy connection attempt coming from the IP address 10.0.1.5, and from a user that has not authenticated yet, what action…

The correct answer is D. User is prompted to authenticate. Only traffic from the user Student will be allowed. If an unauthenticated user attempts a proxy connection matching a policy that requires a specific user or group, the FortiGate will prompt for authentication, and only traffic from the successfully authenticated user matching the policy's criteria will be allowed.

Submitted by deeparc· Apr 18, 2026Firewall Policies and Authentication

Question

Review the exhibit of an explicit proxy policy configuration. If there is a proxy connection attempt coming from the IP address 10.0.1.5, and from a user that has not authenticated yet, what action does the FortiGate proxy take?

Exhibit

NSE4 question #296 exhibit

Options

  • AUser is prompted to authenticate. Traffic from the user Student will be allowed by the policy #1.
  • BUser is not prompted to authenticate. The connection is allowed by the proxy policy #2.
  • CUser is not prompted to authenticate. The connection will be allowed by the proxy policy #1.
  • DUser is prompted to authenticate. Only traffic from the user Student will be allowed.

How the community answered

(46 responses)
  • A
    15% (7)
  • B
    2% (1)
  • C
    9% (4)
  • D
    74% (34)

Why each option

If an unauthenticated user attempts a proxy connection matching a policy that requires a specific user or group, the FortiGate will prompt for authentication, and only traffic from the successfully authenticated user matching the policy's criteria will be allowed.

AUser is prompted to authenticate. Traffic from the user Student will be allowed by the policy #1.

While the user is prompted to authenticate and traffic from the 'Student' user will be allowed by policy #1, the statement in option D is more precise by emphasizing that *only* traffic from that specific user will be allowed by that specific policy in the context of authentication.

BUser is not prompted to authenticate. The connection is allowed by the proxy policy #2.

The user will be prompted to authenticate because the policy requires it. An unauthenticated user cannot simply be allowed by a policy that has explicit user authentication requirements.

CUser is not prompted to authenticate. The connection will be allowed by the proxy policy #1.

The user will be prompted to authenticate. An unauthenticated user cannot fulfill the requirements of a policy that mandates authentication for a specific user or user group.

DUser is prompted to authenticate. Only traffic from the user Student will be allowed.Correct

When an unauthenticated connection from `10.0.1.5` attempts to match an explicit proxy policy (e.g., policy #1) that specifically requires authentication for a user like 'Student', the FortiGate will initiate an authentication challenge. Only if the user successfully authenticates as 'Student' will the policy be matched and their traffic allowed.

Concept tested: Explicit proxy authentication flow

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/602058/proxy-authentication

Topics

#Explicit Proxy#Policy Matching#User Authentication#FortiGate Policies

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice