exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 71 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 71
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibits.
Exhibit A.

Exhibit B.

The exhibit contains a network interface configuration, firewall policies, and a CLI console configuration.
How will FortiGate handle user authentication for traffic that arrives on the LAN interface?

  • A. If there is a fall-through policy in place, users will not be prompted for authentication.
  • B. Authentication is enforced at a policy level; all users will be prompted for authentication.
  • C. All users will be prompted for authentication, users from the Sales group can authenticate successfully with the correct credentials.
  • D. All users will be prompted for authentication, users from the HR group can authenticate successfully with the correct credentials.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
h0p3l3ss
Highly Voted 10 months, 2 weeks ago
Selected Answer: D
Interface LAN(Pport3)is configured to authenticate and only allow HR to access, so the correct answer is D. " All users will be prompted for authentication, users from the HR group can authenticate successfully with the correct credentials"
upvoted 25 times
...
m_farhoud
Most Recent 3 months, 3 weeks ago
i think the firewall policy and the cli user setting are not relevant for the question, its about the authentication at port level so only HR will be allowed --> answer D After that no one will get access because the firewall policy without authentication will never hit.
upvoted 1 times
...
hamidreza0010
5 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
Joggel
6 months ago
Selected Answer: D
Captive Portal on Port 3
upvoted 1 times
...
creed3737
6 months, 1 week ago
Active Authentication Behaviour in Security Study Guide - page 165. this suggests the auth-on-demand makes the answer B.
upvoted 3 times
...
DID123
6 months, 3 weeks ago
Selected Answer: D
I think D make sense
upvoted 1 times
...
giulianorco
7 months, 1 week ago
D is correct. from page 246 in Fortigate Security 7.0 Study Guide. Captive portal authendtication at interface level and is bypassing for specific policy with "set captive-portal-exempt enable" by CLI on policy edit mode.
upvoted 2 times
...
PabloSL
7 months, 1 week ago
Selected Answer: D
ok this clearly needs clarification, correct answer is D, captive portal security enabled means all HTTP requests coming to the interface will return to the auth portal until successfully authenticated, therefore it will not even get to a policy lookup if the user didn't authenticate. D states that HR users can authenticate and are allowed, which is true, they can authenticate and the 2nd rule (in order of precedence) allows traffic for all local_subnet hosts.
upvoted 2 times
m_farhoud
5 months ago
auth-on-demand is set to always which means the 2nd firewall policy is no longer relevant. HR people will be to authenticate (captive portal) but have no access because there is no HR-group in the firewall policy. Answer-D still correct i guess
upvoted 1 times
...
...
borghetti79
7 months, 2 weeks ago
Selected Answer: B
the correct answer is B because the HR user group is not specified in the policies, therefore they will not be able to authenticate
upvoted 2 times
Dylon
5 months ago
Look again mate
upvoted 1 times
...
...
Moustache_Boy
8 months, 1 week ago
The policy states the "sales" group. In the preview shows "HR" (so not the active policy) unless it maybe nested, I think it is C
upvoted 2 times
...
lregu82
9 months, 3 weeks ago
Selected Answer: D
Interface LAN(Pport3)is configured to authenticate and only allow HR to access
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago