Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium
Question 18
What are two features of collector agent advanced mode? (Choose two.)
-
A
A. In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
-
B
B. Advanced mode supports nested or inherited groups.
-
C
C. In advanced mode, security profiles can be applied only to user groups, not individual users.
-
D
D. Advanced mode uses the Windows convention -NetBios: Domain\Username.
Reveal correct answers
Correct answers: A, B
Explanation
A. In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
B. Advanced mode supports nested or inherited groups.
Explanation:
FortiGate's Fortinet Single Sign-On (FSSO) Collector Agent operates in two modes:
Standard Mode – Less flexible, with limited support for nested groups.
Advanced Mode – More powerful, with LDAP integration and support for nested/inherited groups.
Why A is Correct?
FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
In advanced mode, FortiGate directly integrates with LDAP and can retrieve group membership data.
This allows group filtering to be done on FortiGate itself, improving flexibility.
Why B is Correct?
Advanced mode supports nested or inherited groups.
Advanced mode enables FortiGate to recognize and support nested groups, meaning users can inherit permissions from parent groups.
This is essential for organizations with complex Active Directory (AD) structures.
Why C is Incorrect?
Security profiles can be applied only to user groups, not individual users.
Security profiles in FortiGate can still be applied to individual users, not just groups.
Advanced mode enhances group-based policies, but does not restrict security profiles to groups only.
Why D is Incorrect?
Advanced mode uses the Windows convention - NetBios: Domain\Username.
Advanced mode does NOT use NetBIOS formatting (DOMAIN\Username) for authentication.
Instead, it relies on LDAP distinguished names (DNs) and full group membership data.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
