nerdexam
Fortinet

NSE4 · Question #333

Which of the following statements about NTLM authentication are correct? (Choose two.)

The correct answer is A. It is useful when users log in to DCs that are not monitored by a collector agent. C. Multi-domain environments require DC agents on every domain controller.. NTLM authentication is useful for identifying users on domain controllers not monitored by a collector agent, and in multi-domain environments, it requires a DC agent on every domain controller for comprehensive user identification.

Submitted by salim_om· Apr 18, 2026Firewall Policies and Authentication

Question

Which of the following statements about NTLM authentication are correct? (Choose two.)

Options

  • AIt is useful when users log in to DCs that are not monitored by a collector agent.
  • BIt takes over as the primary authentication method when configured alongside FSSO.
  • CMulti-domain environments require DC agents on every domain controller.
  • DNTLM-enabled web browsers are required.

How the community answered

(45 responses)
  • A
    84% (38)
  • B
    11% (5)
  • D
    4% (2)

Why each option

NTLM authentication is useful for identifying users on domain controllers not monitored by a collector agent, and in multi-domain environments, it requires a DC agent on every domain controller for comprehensive user identification.

AIt is useful when users log in to DCs that are not monitored by a collector agent.Correct

NTLM authentication allows a FortiGate to identify users authenticating against domain controllers that might not have a Fortinet Single Sign-On (FSSO) Collector Agent installed or monitored, extending user awareness capabilities in environments where FSSO isn't fully deployed.

BIt takes over as the primary authentication method when configured alongside FSSO.

When FSSO and NTLM are configured, FSSO is generally the primary and more efficient method for user identification, with NTLM often serving as a fallback or for specific legacy authentication scenarios.

CMulti-domain environments require DC agents on every domain controller.Correct

In a multi-domain Active Directory environment, to achieve comprehensive user identification for NTLM (or FSSO), a Fortinet DC Agent must typically be installed on every domain controller in each domain to capture all relevant logon events across the entire infrastructure.

DNTLM-enabled web browsers are required.

While NTLM authentication itself can occur with web browsers for specific applications, the FortiGate's NTLM user identification feature for policy enforcement does not inherently require an NTLM-enabled web browser; it captures NTLM authentication events from the network.

Concept tested: FortiGate NTLM authentication for user identification and FSSO integration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/46944/ntlm-authentication

Topics

#NTLM Authentication#FSSO#Collector Agent#Multi-domain Environments

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice