nerdexam
Fortinet

NSE4 · Question #445

Which of the following statements are correct about NTLM authentication? (Choose three)

The correct answer is A. NTLM negotiation starts between the FortiGate device and the user's browser. B. It must be supported by the user's browser. C. It must be supported by the domain controllers. NTLM authentication involves negotiation between the FortiGate and the user's browser, requires specific browser support, and relies on Windows Domain Controllers for credential validation.

Submitted by chiamaka_o· Apr 18, 2026Firewall and Authentication

Question

Which of the following statements are correct about NTLM authentication? (Choose three)

Options

  • ANTLM negotiation starts between the FortiGate device and the user's browser.
  • BIt must be supported by the user's browser.
  • CIt must be supported by the domain controllers.
  • DIt does not require a collector agent.
  • EIt does not require DC agents.

How the community answered

(42 responses)
  • A
    93% (39)
  • D
    2% (1)
  • E
    5% (2)

Why each option

NTLM authentication involves negotiation between the FortiGate and the user's browser, requires specific browser support, and relies on Windows Domain Controllers for credential validation.

ANTLM negotiation starts between the FortiGate device and the user's browser.Correct

NTLM negotiation typically starts with the FortiGate device initiating a challenge-response process with the user's web browser when configured for NTLM authentication.

BIt must be supported by the user's browser.Correct

For NTLM authentication to function, the user's web browser must be configured to support and engage in the NTLM challenge-response protocol.

CIt must be supported by the domain controllers.Correct

NTLM is a Microsoft authentication protocol that inherently relies on Windows Domain Controllers to authenticate users against the Active Directory database.

DIt does not require a collector agent.

FortiGate's NTLM authentication typically requires a collector agent, such as the FortiGate DC agent or FortiAuthenticator, to communicate with domain controllers and collect user information.

EIt does not require DC agents.

FortiGate's NTLM integration with Active Directory environments usually requires DC agents (like the FortiGate DC agent or a FortiAuthenticator acting as one) to facilitate communication with Domain Controllers.

Concept tested: NTLM authentication process (FortiGate context)

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/523773/ntlm-authentication

Topics

#NTLM Authentication#User Authentication#FortiGate Authentication#Directory Services

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice