exam questions

Exam FCP_FAZ_AD-7.4 All Questions

View all questions & answers for the FCP_FAZ_AD-7.4 exam

Exam FCP_FAZ_AD-7.4 topic 1 question 13 discussion

Actual exam question from Fortinet's FCP_FAZ_AD-7.4
Question #: 13
Topic #: 1
[All FCP_FAZ_AD-7.4 Questions]

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

  • A. A local wildcard administrator account
  • B. An administrator group
  • C. One or more remote LDAP servers
  • D. LDAP servers IP addresses added as trusted hosts
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
12_tst2025
1 month, 2 weeks ago
Selected Answer: AC
same answer as NSE5, mistake on last comment
upvoted 1 times
...
12_tst2025
1 month, 2 weeks ago
Selected Answer: AB
same answer as NSE5
upvoted 1 times
...
truserud
2 months ago
Selected Answer: AC
Page 80 in the study guide specifically states: The Wildcard feautre allows you to authenticate users from on or more groups. One user on FortiAnalyzer that points to a remote authentication server. - NO LOCAL CREDENTIALS ON FORTIANALYZER. You can allow "MATCH ALL USERS ON REMOTE SERVER" option to allow adminsitrators to log into FortiAnalyzer using their credentials on a remote authentication server. This option is useful for creating wildcard administrators and removed the need for FortiAnalyzer to store local credentials. Thus A - A local wildcard administrator and C - One or more LDAP servers should be the correct answers.
upvoted 1 times
...
tovich
2 months, 1 week ago
Selected Answer: B
True that this questionis tricky, but here we have to think about configuring setting for a local wilcard administrator account. Whe you create a local wildcard administrator, after typing tje user name field, you have to choose the admin type (local, radius, ldap, tacas+, pki, group, sso). if you choose local then you enter credentials and this is a local admin account, but if you one of the any remaining option, then you can select a remote server or remote serger group. The anwsers are B and C
upvoted 1 times
...
JoyBoyMx
2 months, 3 weeks ago
Selected Answer: AC
I believe it's A and C Because the local wildcard administrator is not the administrator user itself, this wildcard calls to the remote LDAP users
upvoted 2 times
...
Toh85
3 months, 3 weeks ago
Selected Answer: BC
Correct B and C
upvoted 1 times
...
darkstar15
4 months, 4 weeks ago
The question is difficult to interpret, from my point of view if we respect the order of creating what is requested, first we would have to register the server and then the group. The key word is in the question when it says: a single group. I think "Wildcard" should be ruled out because it is not talking about "multiple remote admin". Correct B and C
upvoted 3 times
...
Slikings
5 months, 1 week ago
This question is tricky. In order to understand it you have to focus on the wording. "non-local" implies to not storing credentials locally on the FAZ. There is no specific interpretation in the study guide on none-local administrators however we can assume that a local wildcard admin would not fufill the non local portion of the question. Therefore B & C is correct.
upvoted 2 times
...
TigerL
5 months, 2 weeks ago
A & C are correct. To ensure non-local administrators can login to a fortinet device, you need: 1. One or more remote LDAP servers configured. 2. Configure local wildcard administrator account by enabling the "Match all users on remote server"
upvoted 3 times
...
migdadcom
5 months, 3 weeks ago
Selected Answer: BC
B & C are correct, most likely
upvoted 3 times
...
DBFront
6 months ago
Selected Answer: BC
B & C are correct, page 80 of the FortiAnalyzer 7.4 Admin Study Guide. The answer cannot be "A" because that is a "local wildcard administrator account" and the question is how to configure to allow "non-local administrators" to authenticate.
upvoted 4 times
truserud
2 months ago
Where it states that you create a wildcard admin for the specific reason to not create local users, and allow remote users to authenticate against remote LDAP servers... So A & C is most correct.
upvoted 1 times
...
...
cheloreina3
6 months, 1 week ago
To allow non-local administrators to authenticate on FortiAnalyzer using any account in an LDAP group, you need to configure two key settings: One or more remote LDAP servers (C): You need to configure LDAP servers so that FortiAnalyzer can authenticate non-local users through LDAP. This allows LDAP users to log in without having to create local accounts on FortiAnalyzer. A local wildcard administrator account (A): The wildcard administrator account allows any user authenticated through the LDAP server to log in as an administrator without creating individual admin accounts. Enabling the "Match all users on remote server" option simplifies authentication.
upvoted 3 times
...
Beatledrew
6 months, 1 week ago
C and D, Page 106 of the Study Guide
upvoted 1 times
JoyBoyMx
2 months, 3 weeks ago
Your answer should be for question 12, not this one
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago