NSE4 · Question #355
Which of the following statements about advanced AD access mode for FSSO collector agent are true? (Choose two.)
The correct answer is B. FortiGate can act as an LDAP client configure the group filters. D. It uses the Windows convention for naming, that is, Domain\Username. The FortiGate in an FSSO advanced AD access mode deployment can act as an LDAP client to query and filter user groups, identifying users using the Windows Domain\Username convention.
Question
Which of the following statements about advanced AD access mode for FSSO collector agent are true? (Choose two.)
Options
- AIt is only supported if DC agents are deployed.
- BFortiGate can act as an LDAP client configure the group filters.
- CIt supports monitoring of nested groups.
- DIt uses the Windows convention for naming, that is, Domain\Username.
How the community answered
(39 responses)- A8% (3)
- B90% (35)
- C3% (1)
Why each option
The FortiGate in an FSSO advanced AD access mode deployment can act as an LDAP client to query and filter user groups, identifying users using the Windows `Domain\Username` convention.
Advanced AD access mode in FSSO is an alternative to deploying DC agents and does not require them; it relies on the FSSO Collector Agent polling Active Directory directly for logon events.
In an FSSO deployment utilizing advanced AD access mode, the FortiGate can function as an LDAP client to directly query Active Directory for retrieving and configuring user group filters for policy application.
While FSSO generally supports the resolution of nested groups, this capability is not exclusively tied to "advanced AD access mode" and can be supported by other FSSO deployment methods as well.
FSSO's integration with Active Directory, including advanced access modes, identifies and processes users using the standard Windows convention for naming, which is typically represented as `Domain\Username`.
Concept tested: FortiGate FSSO Advanced AD Mode
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/339230/single-sign-on
Topics
Community Discussion
No community discussion yet for this question.