NSE7_OTS-7.2 · Question #6
An OT administrator has configured FSSO and local firewall authentication. A user who is part of a user group is not prompted for credentials during authentication. What is a possible reason?
The correct answer is A. FortiGate determined the user by passive authentication. Fortinet Single Sign-On (FSSO) includes a method called passive authentication. This allows FortiGate to identify and authenticate a user based on their existing Windows login session without prompting the user again for credentials. Because of this passive authentication, the…
Question
An OT administrator has configured FSSO and local firewall authentication. A user who is part of a user group is not prompted for credentials during authentication. What is a possible reason?
Options
- AFortiGate determined the user by passive authentication
- BThe user was determined by Security Fabric
- CTwo-factor authentication is not configured with RADIUS authentication method
- DFortiNAC determined the user by DHCP fingerprint method
How the community answered
(32 responses)- A75% (24)
- B3% (1)
- C16% (5)
- D6% (2)
Explanation
Fortinet Single Sign-On (FSSO) includes a method called passive authentication. This allows FortiGate to identify and authenticate a user based on their existing Windows login session without prompting the user again for credentials. Because of this passive authentication, the user will not see a prompt for credentials when accessing resources protected by FortiGate. This behavior is expected in FSSO deployments where FortiGate can retrieve user login information from the domain controller or through the FSSO agent. The other options (Security Fabric, two-factor with RADIUS, FortiNAC DHCP fingerprint) are less relevant to this scenario or would not explain the lack of prompt during authentication.
Topics
Community Discussion
No community discussion yet for this question.