nerdexam
Fortinet

NSE4 · Question #54

Which are two requirements for DC-agent mode FSSO to work properly in a Windows AD environment? [Choose two.]

The correct answer is A. DNS server must properly resolve all workstation names. B. The remote registry service must be running in all workstations. For FSSO in DC-agent mode to function correctly, proper DNS resolution for all workstations is essential, and the remote registry service must be running on workstations to allow the collector agent to query for logon information.

Submitted by marco_it· Apr 18, 2026Firewall and Authentication

Question

Which are two requirements for DC-agent mode FSSO to work properly in a Windows AD environment? [Choose two.]

Options

  • ADNS server must properly resolve all workstation names.
  • BThe remote registry service must be running in all workstations.
  • CThe collector agent must be installed in one of the Windows domain controllers.
  • DA same user cannot be logged in into two different workstations at the same time.

How the community answered

(66 responses)
  • A
    92% (61)
  • C
    3% (2)
  • D
    5% (3)

Why each option

For FSSO in DC-agent mode to function correctly, proper DNS resolution for all workstations is essential, and the remote registry service must be running on workstations to allow the collector agent to query for logon information.

ADNS server must properly resolve all workstation names.Correct

Accurate DNS resolution is critical for FSSO as it helps the Collector Agent map user logon events (which often include hostnames) to the correct IP addresses of the workstations. Without proper DNS, user-to-IP mappings can fail or be inaccurate.

BThe remote registry service must be running in all workstations.Correct

The remote registry service must be running on workstations because the FSSO Collector Agent might query it to verify user sessions or retrieve specific logon information, which is essential for accurate user identification and mapping.

CThe collector agent must be installed in one of the Windows domain controllers.

While a collector agent is required, it does not have to be installed on a Windows domain controller; it can be installed on a standalone server.

DA same user cannot be logged in into two different workstations at the same time.

FSSO can handle scenarios where a user is logged into multiple workstations simultaneously by creating multiple user-to-IP mappings, so this is not a requirement.

Concept tested: FSSO DC-agent mode requirements

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526738/fortinet-single-sign-on-fsso

Topics

#FSSO#Authentication#Active Directory#DC Agent Mode

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice