NSE4 · Question #472
Which of the following statements are true about PKI users created in a FortiGate device? (Choose two.)
The correct answer is A. Can be used for token-based authentication B. Can be used for two-factor authentication. FortiGate user accounts configured with Public Key Infrastructure (PKI) capabilities can integrate with other robust authentication mechanisms.
Question
Which of the following statements are true about PKI users created in a FortiGate device? (Choose two.)
Options
- ACan be used for token-based authentication
- BCan be used for two-factor authentication
- CAre used for certificate-based authentication
- DCannot be members of user groups
How the community answered
(36 responses)- A83% (30)
- C11% (4)
- D6% (2)
Why each option
FortiGate user accounts configured with Public Key Infrastructure (PKI) capabilities can integrate with other robust authentication mechanisms.
FortiGate user accounts, including those enabled for PKI, can be assigned FortiTokens to enable token-based authentication as part of their security profile.
Users configured with PKI can leverage FortiTokens or other methods to implement two-factor authentication, enhancing their security posture.
PKI (Public Key Infrastructure) inherently relates to certificate-based authentication, so it is a primary function for users associated with PKI; however, the question asks for *two* truths and A and B represent additional capabilities for such users.
FortiGate users, regardless of their authentication method (including PKI), can be organized into user groups for simplified policy application and management.
Concept tested: FortiGate PKI user authentication options
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/523415/configuring-user-authentication
Topics
Community Discussion
No community discussion yet for this question.