ExamGecko
Question list
Search
Search

Question 18 - NSE7_NST-7.2 discussion

Report
Export

Refer to the exhibit.

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command

What two conclusions can you draw from the output? (Choose two.)

A.
FSSO is using agentless polling mode to detect logon events.
Answers
A.
FSSO is using agentless polling mode to detect logon events.
B.
The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on
Answers
B.
The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on
C.
The logon event can be seen on the collector agent installed on Windows.
Answers
C.
The logon event can be seen on the collector agent installed on Windows.
D.
FSSO is using DC agent mode to detect logon events.
Answers
D.
FSSO is using DC agent mode to detect logon events.
Suggested answer: C, D

Explanation:

Logon Event on Collector Agent: The debug output indicates that the logon event is recorded, showing that the collector agent on Windows is logging user activities and transmitting this data to the FortiGate.

DC Agent Mode: The presence of detailed logon events and their corresponding metadata, such as the domain and workstation information, suggests that the FortiGate is using DC agent mode. This mode involves an agent installed on the Domain Controller (DC) to capture and forward logon events.

Fortinet Community: How FSSO Works and Troubleshooting Steps (Welcome to the Fortinet Community!) (Fortinet GURU).

asked 18/09/2024
Jorge Fontes
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first