nerdexam
Fortinet

NSE4 · Question #496

Which of the following authentication methods can be used for SSL VPN authentication? (Choose three.)

The correct answer is A. Remote Password Authentication (RADIUS, LDAP) B. Two-Factor Authentication C. Local Password Authentication. FortiGate SSL VPN supports various authentication methods, including local accounts, integration with remote servers like RADIUS/LDAP, and enhanced security via two-factor authentication.

Submitted by sofia.br· Apr 18, 2026Firewall Policies and Authentication

Question

Which of the following authentication methods can be used for SSL VPN authentication? (Choose three.)

Options

  • ARemote Password Authentication (RADIUS, LDAP)
  • BTwo-Factor Authentication
  • CLocal Password Authentication
  • DFSSO
  • ERSSO

How the community answered

(57 responses)
  • A
    91% (52)
  • D
    7% (4)
  • E
    2% (1)

Why each option

FortiGate SSL VPN supports various authentication methods, including local accounts, integration with remote servers like RADIUS/LDAP, and enhanced security via two-factor authentication.

ARemote Password Authentication (RADIUS, LDAP)Correct

FortiGate SSL VPN supports remote password authentication by integrating with external authentication servers such as RADIUS and LDAP, allowing users to authenticate against existing enterprise directories.

BTwo-Factor AuthenticationCorrect

Two-Factor Authentication (2FA) is a supported and recommended method for SSL VPN to enhance security, often implemented using FortiToken or other time-based one-time password (TOTP) solutions.

CLocal Password AuthenticationCorrect

FortiGate SSL VPN can authenticate users against its internal local user database, where user accounts and passwords are created and stored directly on the FortiGate device itself.

DFSSO

FSSO (Fortinet Single Sign-On) is primarily a mechanism for transparently identifying users for firewall policies based on their Windows login, not a direct authentication method for the SSL VPN login portal itself.

ERSSO

RSSO (Remote Single Sign-On) is similar to FSSO, used for obtaining user identity information from external systems for policy enforcement, and is not a direct authentication method for SSL VPN logins.

Concept tested: FortiGate SSL VPN authentication methods

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/378519/authentication

Topics

#SSL VPN#Authentication#Remote Authentication#Two-Factor Authentication

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice