Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE8_812 Exam - Topic 3 Question 64 Discussion

Refer to the exhibit.An HTTPS access proxy is configured to demonstrate its function as a reverse proxy on behalf of the web server it is protecting. It verifies user identity, device identity, and trust context, before granting access to the protected source. It is assumed that the FortiGate EMS fabric connector has already been successfully connected.You need to ensure that ZTNA access through the FortiGate will redirect users to the FortiAuthenticator to perform username/password and multifactor authentication to validate access prior to accessing resources behind the FortiGate.In this scenario, which two further steps need to be taken on the FortiGate? (Choose two.)
A) Create a SAML user/server object referring to the FortiAuthenticator. and C) Create an authentication scheme with the 'method' as SAML.
B) Create an authentication rule that sets the sso-auth-method to the FortiAuthenticator.
D) Create a firewall rule that allows access from the remote endpoint to the resources behind the FortiGate.

Fortinet NSE8_812 Exam - Topic 3 Question 64 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 64
Topic #: 3
[All NSE8_812 Questions]

Refer to the exhibit.

An HTTPS access proxy is configured to demonstrate its function as a reverse proxy on behalf of the web server it is protecting. It verifies user identity, device identity, and trust context, before granting access to the protected source. It is assumed that the FortiGate EMS fabric connector has already been successfully connected.

You need to ensure that ZTNA access through the FortiGate will redirect users to the FortiAuthenticator to perform username/password and multifactor authentication to validate access prior to accessing resources behind the FortiGate.

In this scenario, which two further steps need to be taken on the FortiGate? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A, C

Contribute your Thoughts:

0/2000 characters
Brigette
9 hours ago
We need the SAML user/server for authentication.
upvoted 0 times
...
Cary
6 days ago
Why A?
upvoted 0 times
...
Brigette
11 days ago
I think A and C are the right choices.
upvoted 0 times
...
Skye
16 days ago
This question is tricky.
upvoted 0 times
...
Dana
21 days ago
Just to clarify, is the FortiAuthenticator mandatory for this setup?
upvoted 0 times
...
Luann
26 days ago
Totally agree with A) and B), they make sense for ZTNA.
upvoted 0 times
...
Carrol
1 month ago
A and B make sense, but I’m not sure about the order.
upvoted 0 times
...
Brianne
1 month ago
Wait, do we really need a firewall rule for this? Seems redundant.
upvoted 0 times
...
Florinda
1 month ago
I’m surprised they didn’t mention anything about logging!
upvoted 0 times
...
Benton
2 months ago
I think B) is also crucial for proper authentication flow.
upvoted 0 times
...
Suzan
2 months ago
Wait, why would you need D? Seems unnecessary to me.
upvoted 0 times
...
Tonette
2 months ago
I think B is also essential for proper authentication flow.
upvoted 0 times
...
France
2 months ago
A) and C) are definitely needed for SAML setup.
upvoted 0 times
...
Kimbery
2 months ago
Definitely A and C, those are key steps!
upvoted 0 times
...
Shawnda
2 months ago
I’m a bit confused about whether we need to create the SAML user/server object first or if the authentication rule is more critical.
upvoted 0 times
...
Herminia
3 months ago
This reminds me of a practice question where we had to configure a similar setup. I feel like creating a firewall rule is definitely necessary.
upvoted 0 times
...
Theola
3 months ago
I remember something about needing to set the sso-auth-method, but I can't recall if it should be linked to the FortiAuthenticator specifically.
upvoted 0 times
...
Renea
3 months ago
I think we need to create an authentication scheme with SAML, but I'm not entirely sure if that's the only step needed.
upvoted 0 times
...

Save Cancel