NSE7_OTS-6.4 Exam QuestionsBrowse all questions from this exam

NSE7_OTS-6.4 Exam - Question 13


An OT supervisor has configured LDAP and FSSO for the authentication. The goal is that all the users be authenticated against passive authentication first and, if passive authentication is not successful, then users should be challenged with active authentication.

What should the OT supervisor do to achieve this on FortiGate?

Show Answer
Correct Answer: D

To achieve the goal of using passive authentication (FSSO) first and then falling back to active authentication (LDAP) if the passive authentication is not successful, the OT supervisor needs to configure the FortiGate to attempt authentication on demand. This can be done by setting the 'auth-on-demand' option to 'implicit' under the user settings configuration. This setting ensures that FortiGate will try to use passive authentication first and only prompt for active authentication if the passive method fails.

Discussion

9 comments
Sign in to comment
bigbugOption: C
Sep 23, 2022

C Explanation/Reference: studyguide_page88

Net_Sec2Option: D
Dec 25, 2022

Explanation/Reference: studyguide_page88

ollo79Option: C
Jun 27, 2023

C, auth-on-demand implicit is default

cciesamOption: C
Jan 27, 2023

Ans: C

SpippoloOption: C
Feb 26, 2023

C. When you enable authentication, all the systems will have to authenticated before traffic is placed on egress interface. Alternatively, on the CLI only, you can change the auth-on-demand option to always.

ali_redOption: C
Apr 28, 2023

C for sure

John1216Option: D
Aug 31, 2023

D. Under config user settings configure set auth-on-demand implicit.

azjlmpangOption: C
Oct 17, 2023

C. Configure a firewall policy with FSSO users and place it on the top of list of firewall policies.

GCISystemIntegratorOption: D
Jun 8, 2024

only with the command in D option permit to have passive and active auth. with FSSO no user prompt regardless order of any firewall policy.