nerdexam
Fortinet

NSE4 · Question #429

Which of the following statements are characteristics of a FSSO solution using advanced access mode? (Choose three.)

The correct answer is B. Nested or inherited groups are supported C. Usernames follow the LDAP convention: CN=User, OU=Name, DC=Domain E. Protection profiles can be applied to user groups only. This question focuses on the specific features and behaviors of Fortinet Single Sign-On (FSSO) when configured in advanced access mode.

Submitted by kevin_r· Apr 18, 2026Firewall and Authentication

Question

Which of the following statements are characteristics of a FSSO solution using advanced access mode? (Choose three.)

Options

  • AProtection profiles can be applied to both individual users and user groups
  • BNested or inherited groups are supported
  • CUsernames follow the LDAP convention: CN=User, OU=Name, DC=Domain
  • DUsernames follow the Windows convention: Domain\username
  • EProtection profiles can be applied to user groups only.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    87% (34)
  • D
    8% (3)

Why each option

This question focuses on the specific features and behaviors of Fortinet Single Sign-On (FSSO) when configured in advanced access mode.

AProtection profiles can be applied to both individual users and user groups

While some FortiGate policies can apply to individual users, FSSO advanced access mode emphasizes group-based policies for efficiency and scalability.

BNested or inherited groups are supportedCorrect

FSSO advanced access mode supports nested or inherited groups from Active Directory, allowing for more flexible and detailed group-based policy application based on complex organizational structures.

CUsernames follow the LDAP convention: CN=User, OU=Name, DC=DomainCorrect

In advanced access mode, FSSO often interacts with LDAP directly, and usernames can follow the LDAP Distinguished Name (DN) convention (e.g., CN=User, OU=Name, DC=Domain) for identification.

DUsernames follow the Windows convention: Domain\username

The Windows convention 'Domain\username' is generally used in standard FSSO modes, whereas advanced access mode frequently uses LDAP DNs for user identification due to its deeper integration capabilities.

EProtection profiles can be applied to user groups only.Correct

With FSSO advanced access mode, protection profiles (e.g., firewall policies) are primarily applied to user groups, rather than individual users, simplifying management and leveraging existing directory group structures.

Concept tested: FSSO advanced access mode features

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/339230/fsso-advanced-mode-overview

Topics

#FSSO#Authentication#Advanced Access Mode#User Groups

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice