Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
A.
A local wildcard administrator account
B.
An administrator group
C.
One or more remote LDAP servers
D.
LDAP servers IP addresses added as trusted hosts
The question is difficult to interpret, from my point of view if we respect the order of creating what is requested, first we would have to register the server and then the group.
The key word is in the question when it says: a single group.
I think "Wildcard" should be ruled out because it is not talking about "multiple remote admin".
Correct B and C
This question is tricky. In order to understand it you have to focus on the wording. "non-local" implies to not storing credentials locally on the FAZ. There is no specific interpretation in the study guide on none-local administrators however we can assume that a local wildcard admin would not fufill the non local portion of the question.
Therefore B & C is correct.
A & C are correct.
To ensure non-local administrators can login to a fortinet device, you need:
1. One or more remote LDAP servers configured.
2. Configure local wildcard administrator account by enabling the "Match all users on remote server"
B & C are correct, page 80 of the FortiAnalyzer 7.4 Admin Study Guide.
The answer cannot be "A" because that is a "local wildcard administrator account" and the question is how to configure to allow "non-local administrators" to authenticate.
To allow non-local administrators to authenticate on FortiAnalyzer using any account in an LDAP group, you need to configure two key settings:
One or more remote LDAP servers (C): You need to configure LDAP servers so that FortiAnalyzer can authenticate non-local users through LDAP. This allows LDAP users to log in without having to create local accounts on FortiAnalyzer.
A local wildcard administrator account (A): The wildcard administrator account allows any user authenticated through the LDAP server to log in as an administrator without creating individual admin accounts. Enabling the "Match all users on remote server" option simplifies authentication.
Your answer should be for question 12, not this one
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
JoyBoyMx
6 days, 23 hours agoToh85
1 month agodarkstar15
2 months, 1 week agoSlikings
2 months, 2 weeks agoTigerL
2 months, 3 weeks agomigdadcom
3 months agoDBFront
3 months, 1 week agocheloreina3
3 months, 2 weeks agoBeatledrew
3 months, 2 weeks agoJoyBoyMx
1 week ago