nerdexam
Fortinet

NSE4_FGT_AD-7.6 · Question #38

A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?

The correct answer is A. The DC agent sends login event data directly to FortiGate. In DC Agent mode, the DC agent installed on the Domain Controller captures the logon events (e.g., Event ID 4624) in real-time. It then pushes this information to the Collector Agent. The Collector Agent, which runs as a service on a dedicated machine, is responsible for…

System Configuration

Question

A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?

Options

  • AThe DC agent sends login event data directly to FortiGate.
  • BThe user logs into the windows domain.
  • CThe collector agent forwards login event data to FortiGate.
  • DFortiGate determines user identity based on the IP address in the FSSO list.

How the community answered

(23 responses)
  • A
    70% (16)
  • B
    17% (4)
  • C
    9% (2)
  • D
    4% (1)

Explanation

In DC Agent mode, the DC agent installed on the Domain Controller captures the logon events (e.g., Event ID 4624) in real-time. It then pushes this information to the Collector Agent. The Collector Agent, which runs as a service on a dedicated machine, is responsible for consolidating this information and then forwarding it to the FortiGate firewall. The FortiGate receives this data and uses the user's IP address to apply appropriate security policies.

Topics

#FSSO#DC agent mode#collector agent#user authentication

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT_AD-7.6 Practice