nerdexam
Fortinet

NSE4 · Question #493

Which are valid replies from a RADIUS server to an ACCESS-REQUEST packet from a FortiGate? (Choose two.)

The correct answer is A. ACCESS-CHALLENGE D. ACCESS-REJECT. A RADIUS server can respond to a FortiGate's ACCESS-REQUEST packet with either an ACCESS-CHALLENGE, requiring further information, or an ACCESS-REJECT, denying access.

Submitted by minji_kr· Apr 18, 2026Firewall and Authentication

Question

Which are valid replies from a RADIUS server to an ACCESS-REQUEST packet from a FortiGate? (Choose two.)

Options

  • AACCESS-CHALLENGE
  • BACCESS-RESTRICT
  • CACCESS-PENDING
  • DACCESS-REJECT

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    3% (1)
  • C
    6% (2)

Why each option

A RADIUS server can respond to a FortiGate's ACCESS-REQUEST packet with either an ACCESS-CHALLENGE, requiring further information, or an ACCESS-REJECT, denying access.

AACCESS-CHALLENGECorrect

An ACCESS-CHALLENGE packet is a standard RADIUS reply indicating that the authentication server needs additional information or a secondary response from the client before it can make a final access decision.

BACCESS-RESTRICT

ACCESS-RESTRICT is not a standard RADIUS packet type for replies to an ACCESS-REQUEST.

CACCESS-PENDING

ACCESS-PENDING is not a standard RADIUS packet type for replies to an ACCESS-REQUEST.

DACCESS-REJECTCorrect

An ACCESS-REJECT packet is a standard RADIUS reply directly denying the authentication request, meaning the user's credentials were not accepted or authorization failed.

Concept tested: RADIUS authentication message types

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/684701/configuring-radius-server-for-authentication

Topics

#RADIUS protocol#Authentication#FortiGate authentication#Protocol messages

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice