NSE 6 – FortiAuthenticator 6.4 — Question 10
An administrator has an active directory (AD) server integrated with FortiAuthenticator. They want members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls.
How does the administrator accomplish this goal?
Answer options
- A. Configure a FortiGate filter on FortiAuthenticator.
- B. Configure a domain groupings list to identify the desired AD groups.
- C. Configure fine-grained controls on FortiAuthenticator to designate AD groups.
- D. Configure SSO groups and assign them to FortiGate groups.
Correct answer: A
Explanation
The correct answer is A, as configuring a FortiGate filter on FortiAuthenticator allows the administrator to specify which AD groups are permitted to participate in FSSO. Options B and C do not directly enforce participation in FSSO, and option D pertains to a different grouping method that does not restrict AD group access specifically.