FCP-FGT-AD domain - 20% of the exam

Firewall policies and authentication

Firewall policies and authentication is 20% of the FCP - FortiGate Administrator (FCP-FGT-AD) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleFirewall policies and authenticationhard

A network administrator is deploying FSSO in DC agent mode for a Windows Active Directory domain with three domain controllers. Each user logon must be captured and forwarded to the collector agent so that the FortiGate can apply identity-based policies. Which component must be installed on each monitored domain controller for this mode to function?

  • AA DC agent (dcagent.dll) registered on every monitored domain controller, which intercepts logon events and forwards them to the collector agent. Correct
  • BA collector agent installed directly on every domain controller, so each controller independently sends user-to-IP mappings to the FortiGate.
  • CA TS agent on each domain controller to track per-session source ports for users sharing one host.
  • DThe FortiGate polling service enabled against each controller, removing the need for any agent on the controllers.
Identify that FSSO DC agent mode requires a DC agent installed on each monitored domain controller to capture logon events. In DC agent mode the dcagent.dll is loaded on each domain controller and intercepts user logon events in real time, forwarding them to the collector agent, which then sends consolidated user-to-IP-to-group mappings to the FortiGate. This per-controller agent is what separates DC agent mode from agentless polling.

Why A is correct: DC agent mode requires the FSSO DC agent to be installed on each domain controller; it hooks logon events at the source and pushes them to the collector agent, which is the defining characteristic of this mode.

Why B is wrong: It is tempting because the collector agent is central to FSSO, but in DC agent mode the collector is a single (or redundant) service that aggregates events from DC agents, not a per-controller component that talks to the FortiGate alone.

Why C is wrong: The TS agent is used for Citrix or Terminal Server environments to distinguish users on a shared host by port range, not for capturing standard domain controller logon events.

Why D is wrong: This describes agentless polling mode rather than DC agent mode; the question explicitly specifies DC agent mode, which depends on an installed DC agent rather than FortiGate-initiated polling.

Other domains in this exam

See also the FCP-FGT-AD cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by Fortinet. Original, blueprint-aligned practice material only.