FSSO II

Beschreibung

NSE4 6.0 NSE4 6.0 Quiz am FSSO II, erstellt von Marcos Avila am 25/07/2018.
Marcos Avila
Quiz von Marcos Avila, aktualisiert more than 1 year ago
Marcos Avila
Erstellt von Marcos Avila vor fast 6 Jahre
401
1

Zusammenfassung der Ressource

Frage 1

Frage
TCP ports 139 its optional, only TCP port 445 must be opened between collector agents or FortiGate and all hosts.
Antworten
  • True
  • False

Frage 2

Frage
Which is the recommended mode for FSSO deployments?
Antworten
  • a. DC agent mode
  • b. Polling mode: Agentless

Frage 3

Frage
Which FSSO mode requires more FortiGate system resources (CPU and RAM)?
Antworten
  • a. Polling mode: Collector agent-based
  • b. Polling mode: Agentless

Frage 4

Frage
Is a suite of Microsoft security protocols that provides authentication, integrity, and confidentiality to users.
Antworten
  • NTLM
  • WinSecLog
  • NetAPI
  • WMI

Frage 5

Frage
NTLM
Antworten
  • NT LAN Manager
  • Network LAN Microsoft

Frage 6

Frage
Simple domain configurations for NTLM authentication
Antworten
  • a. do not require a DC agent
  • b. require only one global collector agent

Frage 7

Frage
When performing NTLM authentication, what information does the web browser supply to FortiGate?
Antworten
  • a. The user's credentials (username and password)
  • b. The user’s user ID, IP address, and group membership

Frage 8

Frage
Which of the following may cause an NTLM authentication to occur?
Antworten
  • a. Traffic coming from an IP on the F850 user list
  • b. Traffic coming from an IP not on the FSSO user list

Frage 9

Frage
The FSSO collector agent can access Windows AD in one of two modes:
Antworten
  • Standard Advanced
  • Agent mode Polling mode

Frage 10

Frage
Notice that you do not need to match the F880 version with your exact FortiGate firmware version. When installing FSSO, grab the latest collector agent for your major release. You do however, need to match the dcagent version to the collector agent version.
Antworten
  • True
  • False

Frage 11

Frage
The maximum number of Windows AD user groups allowed on a FortiGate depends on the model.
Antworten
  • Low-end FortiGate models support 256 Windows AD user groups. Mid-range and high-end models can support more groups. This is per VDOM, if VDOMs are enabled on FortiGate.
  • Low-end FortiGate models support 526 Windows AD user groups. Mid-range and high-end models can support more groups. This is per VDOM, if VDOMs are enabled on FortiGate.

Frage 12

Frage
This setting controls when the collector agent connects to individual workstations on port 139 (or port 445), and uses the remote registry service to verify if a user is still logged on to the same station. It changes the status of the user under Show logon User, to not verified when it cannot connect to the workstation. If it does connect, it verifies the user and the status remains OK. To facilitate this verification process, the remote registry service should be set to auto start on all domain member PCs.
Antworten
  • Workstation verify Interval.
  • Dead entry timeout Interval.
  • IP address change verify Interval.
  • Cache user group lookup result.

Frage 13

Frage
This setting applies only to entries with an unverified status. When an entry is not verified, the collector starts this timer. It‘s used to age out the entry. When the timer expires, the logon is removed from the collector. From FortiGate’s perspective, there is no difference between entries that are OK and entries that are not verified. Both are considered valid.
Antworten
  • Dead entry timeout Interval.
  • Workstation verify Interval.
  • IP address change verify Interval.
  • Cache user group lookup result.

Frage 14

Frage
This setting checks the IP addresses of logged in users and updates the FortiGate when a user‘s IP addresses change. This timer is especially important in DHCP or dynamic environments to prevent users from being locked out if they change lP addresses. The domain's DNS server should be accurate; if the DNS server does not update the affected records promptly, the collector agent's lP information will be inaccurate.
Antworten
  • IP address change verify Interval.
  • Workstation verify Interval.
  • Dead entry timeout Interval.
  • Cache user group lookup result.

Frage 15

Frage
This setting caches the user group membership for a defined period of time. It is not updated, even if the user changes group membership in AD.
Antworten
  • Cache user group lookup result.
  • IP address change verify Interval.
  • Dead entry timeout Interval.
  • Workstation verify Interval.

Frage 16

Frage
Uses the Windows convention NetBios: Domain\Username.
Antworten
  • Standard mode
  • Advanced mode

Frage 17

Frage
Uses the LDAP convention: CN=User, OU=Name, DC=Domain.
Antworten
  • Standard mode
  • Advanced mode

Frage 18

Frage
AD Group support (Select 4)
Antworten
  • Security groups
  • Universal groups
  • Groups inside OUs
  • Local or universal groups that contain universal groups from child domains (only with Global Catalog)
  • Global Catalog
  • Local groups

Frage 19

Frage
If you have collector agents, either using the DC agent mode or the collector agent-based polling mode, what 880 setting should you select on FortiGate?
Antworten
  • a. Poll Active Directory Server
  • b. Fortinet Single—Sign-On Agent

Frage 20

Frage
Filtering from FortiGate can only be done if the collector agent is in which AD access mode?
Antworten
  • a. Standard
  • b. Advanced

Frage 21

Frage
Which of the following naming conventions does the F880 collector agent use to access the Windows AD in Standard access mode?
Antworten
  • a. Windows convention — NetBios: Domain\Username
  • b. LDAP convention: CN=User, OU=Name, DC=Domain

Frage 22

Frage
Which logging level shows the logon events on the collector agent?
Antworten
  • a. Information
  • b. Warning

Frage 23

Frage
The command diagnose debug fsso-polling detail displays information for which mode of FSSO?
Antworten
  • a. Agentless polling mode
  • b. Collector agent based polling mode
Zusammenfassung anzeigen Zusammenfassung ausblenden

ähnlicher Inhalt

Historische Fakten des 20. Jahrhunderts
AntonS
Esperanto - Regeln der Grammatik
JohannesK
Alkalimetalle
Cassibodua
2 C Entwicklungspsychologie März 2012
petra.drewitz
Die Verwandlung von Franz Kafka
barbara91
Top Tools für Zusammenarbeit im Web 2.0
Gaby K. Slezák
BM 13 - Allgemeine Didaktik
Isabell St
DELF B1/B2 Vocabulaire 1/...
Chiara Braun
Kurvendiskussion bei gebrochen rationalen Funktionen
berit.krondorf
Grundzüge Soziologie Richter
Kamila rURKA
Vetie Pharma 2015
Anna Auferkamp