exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 1 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 1
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Which two statements about FortiGate FSSO agentless polling mode are true? (Choose two.)

  • A. FortiGate uses the AD server as the collector agent.
  • B. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
  • C. FortiGate does not support workstation check.
  • D. FortiGate directs the collector agent to use a remote LDAP server.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PonPom3
Highly Voted 1 year, 10 months ago
Agentless Polling Mode Similar to agent-based pollen, but FortiGate polls instead Doesn't require an external DC agent or collector agent Fortigate collects data directly Event logging must be enabled on the DCs More CPU and RAM require by FortiGate Support for pollen option WinSecLog only Fortigate uses SMB TCP 445 protocol to read the event viewer logs Fewer available features that collector agent-base polling mode Fortigate doesn't poll workstation
upvoted 10 times
...
Fati1995
Most Recent 3 months ago
Selected Answer: BC
"FortiGate uses the SMB protocol to read the event viewer logs" "FortiGate doesn't poll workstation. Workstation verification is not available in agentless polling mode"
upvoted 1 times
...
raydel92
10 months, 2 weeks ago
Selected Answer: BC
Slide 16, Chapter 3 - Fortinet Single Sign-On (FSSO), Course "NSE 4 FortiGate Infrastructure 7.2 Self-Paced" - "FortiGate uses the SMB protocol to read the event viewer logs" - "FortiGate doesn't poll workstation. Workstation verification is not available in agentless polling mode"
upvoted 2 times
...
RabbitB
1 year ago
Selected Answer: BC
Agentless polling mode operates in a similar way to WinSecLog, but with only two event IDs: 4768 and 4769. Because there’s no collector agent, FortiGate uses the SMB protocol to read the event viewer logs from the DCs. In agentless polling mode, FortiGate acts as a collector. It is responsible for polling on top of its normal FSSO tasks but does not have all the extra features, such as workstation checks, that are available with the external collector agent. FortiGate Infrastructure 7.2 Study Guide P.130
upvoted 1 times
...
nick212121
1 year, 1 month ago
B & C Fortigate doesnt poll workstation
upvoted 1 times
...
vlsoft
1 year, 2 months ago
Selected Answer: BC
It's B and C (not A and B)
upvoted 1 times
...
Vingador3000
1 year, 2 months ago
Selected Answer: BD
BD, nse4
upvoted 1 times
...
einstein85
1 year, 3 months ago
Selected Answer: BD
B and D are correct: https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732
upvoted 1 times
...
DriftandLuna
1 year, 3 months ago
Selected Answer: BC
Pg 272 Inf study guide : Because there’s no collector agent, FortiGate uses the SMB protocol to read the event viewer logs from the DCs. In agentless polling mode, FortiGate acts as a collector. It is responsible for polling on top of its normal FSSO tasks but does not have all the extra features, such as workstation checks, that are available with the external collector agent
upvoted 3 times
...
carbonblack
1 year, 3 months ago
BC 100%. It asks for AgentLESS, see https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-FSSO-agentless-polling/ta-p/214349 And check NSE5 Forticlient EMS.
upvoted 1 times
carbonblack
1 year, 3 months ago
And answer D would be impossible, since it's AgentLESS so no Collector Agent to direct anywhere lol
upvoted 1 times
...
...
Net_Boy_26
1 year, 3 months ago
Selected Answer: AD
FSSO (Fortinet Single Sign-On) agentless polling mode is a method used by Fortinet devices, such as FortiGate firewalls, to collect user authentication information from Microsoft Active Directory (AD) servers. In agentless polling mode, FortiGate reads the event viewer logs directly from the domain controllers (DCs) using the SMB protocol. The event viewer logs contain information about user logins, logouts, and other authentication events. The FSSO collector agent is not required in agentless polling mode, as FortiGate directly reads the event viewer logs from the DCs. This reduces the configuration complexity and overhead associated with deploying a collector agent on the network. FortiGate uses the collected authentication information to apply security policies and provide user-based reporting. This allows Fortinet devices to enforce granular policies based on user identity, rather than just IP addresses.
upvoted 1 times
...
Net_Boy_26
1 year, 3 months ago
Selected Answer: BD
Option C is incorrect because FortiGate does support workstation check in agentless polling mode.
upvoted 2 times
...
Net_Boy_26
1 year, 3 months ago
B and D is the correct answer Reference: https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732
upvoted 1 times
...
BUZOMD
1 year, 4 months ago
Selected Answer: BC
Page 257 student guie infrastructure 7.0 => Fortigate used SMB protocoll to read the event viewer logs from DC's. Workstation verficaction is not available in agentless polling mode. Fortigate acts as a collector. its responsible for polling on top of its normal FSSO taks buts does not have all the extra features, such as workstation checks, that are available with the external collector agent
upvoted 1 times
...
missaw84
1 year, 4 months ago
BD ist correct
upvoted 1 times
...
[Removed]
1 year, 5 months ago
Correct answer is C & D Reference **Fortigate Infrastructure Study Guide Page 272**
upvoted 1 times
...
alexeid72
1 year, 5 months ago
Correct answer is B and D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago