exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 40 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 40
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

Refer to the exhibit.

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?

  • A. The Service DNS is required in the firewall policy.
  • B. The user is using an incorrect user name.
  • C. The Remote-users group is not added to the Destination.
  • D. No matching user account exists for this user.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fa7474b
Highly Voted 2 months ago
Selected Answer: A
Just confirmed the answer is A by replicating this config on my Fortigate. If you don't add DNS to the policy you just get a timeout and the browser cannot find the site. Once you add DNS you get a prompt that you must log in to access the internet. I think the confusing part of this question is that it reads as if the user is able to access the internet and is not being prompted. When in fact, they are not getting prompted AND they can't access the internet.
upvoted 6 times
...
Kunot
Most Recent 15 hours, 36 minutes ago
Selected Answer: D
what if user account is not on remote-user?
upvoted 1 times
...
vuhidus
3 weeks, 4 days ago
Selected Answer: A
A. The Service DNS is required in the firewall policy.
upvoted 1 times
...
s4mu3l007
1 month, 2 weeks ago
are correct, A
upvoted 1 times
...
herlock_sholmes_2810
2 months, 4 weeks ago
Selected Answer: A
A. The Service DNS is required in the firewall policy. "DNS traffic can be allowed if user has not authenticated yet Hostname resolution is often required by the application layer protocol (HTTP/HTTPS/FTP/Telnet) that is used to authenticate DNS service must be explicity listed as a service in the policy" Reference: FortiGate 7.4 Administration Study Guide, page 115 (Firewall Policy - Service)
upvoted 1 times
...
Knocks
3 months ago
Selected Answer: A
It cannot be B, also because the user is never promped to login.
upvoted 2 times
miguelmagr
2 months, 2 weeks ago
If you selected B it says that you are only being advised that the username/password is incorrect and you can re-type the credentials but the login prompt would appear.
upvoted 1 times
...
...
TIGERZ44
3 months, 1 week ago
Selected Answer: A
A firewall policy also checks the service in order to transport the named protocols or group of protocols. No service (with the exception of DNS) is allowed through the firewall policy before successful user authentication. DNS is usually used by HTTP so that people can use domain names for websites, instead of their IP address. DNS is allowed because it is a base protocol and will most likely be required to initially see proper authentication protocol traffic. Hostname resolution is almost always a requirement for any protocol. However, the DNS service must still be defined in the policy as allowed, in order for it to pass. A is the correct answer
upvoted 2 times
...
wsdeffwd
3 months, 1 week ago
Selected Answer: A
Page 115
upvoted 4 times
...
bob511
3 months, 2 weeks ago
A. page 115 in fortigate 7.4 admin guide
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago