nerdexam
Fortinet

NSE4 · Question #51

With FSSO, a domain user could authenticate either against the domain controller running the collector agent and domain controller agent, or a domain controller running only the domain controller…

The correct answer is A. The login event is sent to the collector agent. C. The domain collector agent may perform a DNS lookup for the authenticated client's IP address. When a user authenticates against a domain controller with only the FSSO DC agent, the login event is forwarded to the central collector agent, which may then perform DNS lookups for the client's IP.

Submitted by sofia.br· Apr 18, 2026Firewall and Authentication

Question

With FSSO, a domain user could authenticate either against the domain controller running the collector agent and domain controller agent, or a domain controller running only the domain controller agent. If you attempt to authenticate with a domain controller running only the domain controller agent, which statements are correct? (Choose two.)

Options

  • AThe login event is sent to the collector agent.
  • BThe FortiGate receives the user information directly from the receiving domain controller agent of
  • CThe domain collector agent may perform a DNS lookup for the authenticated client's IP address.
  • DThe user cannot be authenticated with the FortiGate in this manner because each domain

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    8% (2)
  • D
    13% (3)

Why each option

When a user authenticates against a domain controller with only the FSSO DC agent, the login event is forwarded to the central collector agent, which may then perform DNS lookups for the client's IP.

AThe login event is sent to the collector agent.Correct

The FSSO Domain Controller (DC) agent's primary role is to monitor login events on the DC it's installed on and forward these events to the central FSSO Collector Agent for processing. This ensures that even if a DC doesn't host the Collector Agent, its login events are captured.

BThe FortiGate receives the user information directly from the receiving domain controller agent of

The FortiGate receives user information and IP mappings from the FSSO Collector Agent, not directly from individual DC agents.

CThe domain collector agent may perform a DNS lookup for the authenticated client's IP address.Correct

The FSSO Collector Agent needs to map the authenticated user to their workstation's IP address to create the user-to-IP mapping on the FortiGate; it performs DNS lookups to resolve the IP address if the login event provides a hostname instead of an IP, or to confirm workstation details.

DThe user cannot be authenticated with the FortiGate in this manner because each domain

The user can be authenticated in this manner, as DC agents are designed to forward login events to a central collector agent for processing and FortiGate integration.

Concept tested: FSSO DC Agent and Collector Agent roles

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526738/fortinet-single-sign-on-fsso

Topics

#FSSO#Authentication#Collector Agent#Domain Controller Agent

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice