Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium
Question 22
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
-
A
A. FortiGate uses the AD server as the collector agent.
-
B
B. FortiGate directs the collector agent to use a remote LDAP server.
-
C
C. FortiGate does not support workstation check.
-
D
D. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
Reveal correct answers
Correct answers: C, D
Explanation
Correct Answers: C and D
Explanation:
FortiGate FSSO (Fortinet Single Sign-On) Agentless Polling Mode allows FortiGate to retrieve user login information directly from Active Directory (AD) without requiring an external Collector Agent. Instead, FortiGate polls the domain controllers (DCs) for authentication events.
Why C is Correct? → FortiGate does not support workstation check.
In agent-based mode, the Collector Agent can check the status of the workstation (e.g., if the user is still logged in).
In agentless polling mode, FortiGate does not perform workstation checks because it only reads authentication events from the domain controller logs.
Why D is Correct? → FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
In agentless polling mode, FortiGate queries the Windows Security Event Logs on the domain controllers (DCs).
FortiGate does this using SMB (Server Message Block) protocol to access event logs and retrieve user login events.
This method allows FortiGate to map users to IP addresses based on authentication logs.
Why A is Incorrect? → FortiGate uses the AD server as the collector agent.
Incorrect, because in agentless mode, FortiGate does not rely on a separate Collector Agent.
Instead, FortiGate directly polls the domain controllers (DCs) for authentication events.
Why B is Incorrect? → FortiGate directs the collector agent to use a remote LDAP server.
Incorrect, because in agentless mode, FortiGate does not use a Collector Agent at all.
LDAP is used for querying user groups but is not used for polling Windows Event Logs in this mode.
Final Answer: C and D
FortiGate agentless polling mode lacks workstation checks (C) and retrieves logs via SMB from the domain controller event viewer logs (D).
Reference:
C. and D.
Agenteless Polling Mode - Doesn't require an external DC agent or collector agent - - FortiGate collects the data directly - Event logging must be enabled on the DCs - More CPU and RAM required by FortiGate - Support for polling option WinSecLog only - - FortiGate uses the SMB protocol to read the event viewer logs - Fewer available features than collector agent-based polling mode - FortiGate doesn't poll workstation - - Workstation verification is not available in agentless polling mode Reference: FortiGate 7.4 Administration Study Guide, page 132
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
