QuestionQ1
Fortinet Single Sign-On (FSSO)A new administrator is setting up FSSO authentication on FortiGate in DC Agent Mode.
Which step is not included in the expected process?
- A The user logs into the windows domain.
- B FortiGate determines user identity based on the IP address in the FSSO list.
- C The DC agent sends login event data directly to FortiGate.
- D The collector agent forwards login event data to FortiGate.
QuestionQ2
RoutingRefer to the exhibit.

Based on the routing table in the exhibit, which two statements are correct?
- A A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.
- B A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.
- C A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.
- D A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.
Community Discussion
QuestionQ3
Fortinet Single Sign-On (FSSO)An administrator believes that the Collector Agent is not sending login events to FortiGate.
What is the most effective troubleshooting action?
- A Verify if DC agent is enabled on the FortiGate.
- B Restart the domain controller to refresh authentication services.
- C Check if TCP port 8000 is open between the collector agent and FortiGate.
- D Verify if FortiGate is set to use LDAP authentication instead of FSSO.
Community Discussion
QuestionQ4
SD-WAN Configuration and MonitoringRefer to the exhibit showing an SD-WAN zone configuration in the FortiGate GUI.

Based on the exhibit, which statement is correct?
- A The Underlay zone contains no member.
- B port2 and port3 are not assigned to a zone.
- C The Underlay zone is the zone by default.
- D The virtual-wan-link and overlay zones can be deleted.
Community Discussion
QuestionQ5
Web FilteringRefer to the exhibits.


An administrator has configured the Web Filter Profile to block access to every social networking site except Facebook. However, when users attempt to reach Facebook.com, they are redirected to a FortiGuard web-filtering block page.
Based on the exhibits, which configuration change must the administrator make to permit Facebook while blocking every other social networking site?
- A Set the Social Networking action as warning in the FortiGuard Category Based Filter.
- B Change the Feature set of Web Filter Profile as Proxy-based.
- C Set the Action as Exempt for www.facebook.com in the Static URL Filter.
- D Change the type as Simple in the Static URL Filter section.

















Community Discussion