Exam NSE7_FSN_AR-7.6 Topic 1 Question 20 Discussion
Actual exam question for Fortinet's NSE7_FSN_AR-7.6 exam
Question #: 20
Topic #: 1
Question #: 20
Topic #: 1
Refer to the exhibits.

The system administrator settings configured on the root FortiGate and the Security Fabric settings configured on a downstream FortiGate are shown.
When prompted to sign in with Security Fabric to the downstream FortiGate, a user enters the single sign-on (SSO) provider credentials.
What happens next for the user?

The system administrator settings configured on the root FortiGate and the Security Fabric settings configured on a downstream FortiGate are shown.
When prompted to sign in with Security Fabric to the downstream FortiGate, a user enters the single sign-on (SSO) provider credentials.
What happens next for the user?
Suggested Answer: B Vote an answer
The Enterprise Firewall 7.6 Administrator Study Guide explains: "The root FortiGate acts as the identity provider (IdP) and you configure the other devices as service providers (SP)." Therefore, the root FortiGate authenticates the credentials for the AdminSSO administrator, while the downstream FortiGate operates as the SAML service provider.
After successful authentication, the root FortiGate returns a SAML assertion to the downstream FortiGate.
The downstream device then grants access according to its configured SAML administrator profile. The exhibit shows that its Default admin profile is super_admin_readonly. Consequently, the user is logged in to the downstream FortiGate with read-only super-administrator privileges.
The browser can be redirected temporarily to the root FortiGate for identity-provider authentication, but that is not the final access outcome, so option A is incomplete. AdminSSO is the administrator account name, not an access profile, and the user is not left on the root FortiGate, eliminating option C. Because the credentials are successfully authenticated, option D is also incorrect.
References: Enterprise Firewall 7.6 Administrator Study Guide, Security Fabric - Use Case 4: Security Fabric with SAML SSO , page 266; FortiOS 7.6 - Configuring a downstream FortiGate as an SP ; FortiOS 7.6
- SSO administrators .
After successful authentication, the root FortiGate returns a SAML assertion to the downstream FortiGate.
The downstream device then grants access according to its configured SAML administrator profile. The exhibit shows that its Default admin profile is super_admin_readonly. Consequently, the user is logged in to the downstream FortiGate with read-only super-administrator privileges.
The browser can be redirected temporarily to the root FortiGate for identity-provider authentication, but that is not the final access outcome, so option A is incomplete. AdminSSO is the administrator account name, not an access profile, and the user is not left on the root FortiGate, eliminating option C. Because the credentials are successfully authenticated, option D is also incorrect.
References: Enterprise Firewall 7.6 Administrator Study Guide, Security Fabric - Use Case 4: Security Fabric with SAML SSO , page 266; FortiOS 7.6 - Configuring a downstream FortiGate as an SP ; FortiOS 7.6
- SSO administrators .
by Ophelia at Aug 25, 2026, 12:44 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).