Which statement is one disadvantage of using FSSO NetAPI polling mode over FSSO Security Event Log (WinSecLog) polling mode?〖使用FSSO NetAPI轮询模式与FSSO安全事件日志(WinSecLog)轮询模式的一个缺点是哪个?〗
A. It requires a DC agent installed in some of the Windows DC. 〖它需要在一些Windows域控制器上安装一个DC代理〗
B. It runs slower. 〖它运行慢〗
C. It might miss some logon events.〖它可能会错过一些登录事件〗
D. It requires access to a DNS server for workstation name resolution.〖它需要为工作站名称解析访问DNS服务器〗
【分析】
NetAPI polling 模式可能会因为DC的高负荷而丢失一部分登录事件。
【答案】C
Which statement describes what the CLI command diagnose debug authd fsso list is used for?〖哪些声明描述了CLI命令 diagnose debug authd fsso list 是用来做什么的?〗
A. Monitors communications between the FSSO collector agent and FortiGate unit. 〖监视FSSO收集代理与FortiGate设备之间的通信〗
B. Displays which users are currently logged on using FSSO. 〖显示当前使用FSSO登录的用户〗
C. Displays a listing of all connected FSSO collector agents. 〖显示所有连接FSSO收集器代理的清单〗
D. Lists all DC Agents installed on all domain controllers. 〖列出所有安装在所有域控制器上DC代理〗
【分析】
通过在CLI上输入命令:diagnose debug authd fsso list,可以看到有域帐户登录的信息,信息是FSSO收集代理传送给防火墙的。
【答案】B
FSSO provides a single sign on solution to authenticate users transparently to a FortiGate unit using credentials stored in Windows active directory.〖FSSO提供一个单点登录解决方案在Windows活动域使用证书存储到一个FortiGate设备透明地验证用户〗
A. An FSSO collector agent must be installed on every domain controller.〖FSSO收集器代理必须安装在每一个域控制器〗
B. An FSSO domain controller agent must be installed on every domain controller.〖FSSO域控制器代理必须安装在每一个域控制器〗
C. The FSSO domain controller agent will regularly update user logon information on the FortiGate unit.〖FSSO域控制器代理将在FortiGate设备上定期更新用户登录信息〗
D. The FSSO collector agent will receive user logon information from the domain controller agent and will send it to the FortiGate unit.〖FSSO收集器代理会收到从域控制器代理得到的用户登录信息并发送到FortiGate设备〗
【分析】
需要在每个DC上安装Domain Controller (DC) agent,FSSO collector agent 可以安装在非域控制器上。
【答案】BD
Which are two requirements for DC-agent mode FSSO to work properly in a Windows AD environment? (Choose two)〖DC代理模式FSSO正常工作在一个Windows域环境需要满足哪两个条件? (选择两个)〗
A. DNS server must properly resolve all workstation names.〖DNS服务必须妥善解决所有工作站名称〗
B. The remote registry service must be running in all workstations.〖必须在所有的工作站运行远程注册服务〗
C. The collector agent must be installed in one of the Windows domain controllers.〖收集代理必须安装在Windows域控制器〗
D. A same user cannot be logged in into two different workstations at the same time.〖相同的用户无法在同一时间登录到两个不同的工作站〗
【分析】
FSSO AD需要DNS能解析所有的workstation的主机名,每个workstation上必须运行远程注册服务。
【答案】AB
With FSSO, a domain user could authenticate either against the domain controller running the collector agent and domain controller agent, or a domain controller running only the domain controller agent. 〖用FSSO,一个域用户可以验证域控制器运行收集器代理和域控制器代理,或者域控制器只运行域控制器代理〗
If you attempt to authenticate with a domain controller running only the domain controller agent, which statements are correct? (Choose two)〖如果你试图验证域控制器只运行域控制器代理,哪些描述是正确的?(选择两个)〗
A. The login event is sent to the collector agent.〖登录事件发送到收集器代理〗
B. The FortiGate receives the user information directly from the receiving domain controller agent of the secondary domain controller.〖FortiGate直接从铺助域控制器的域控制器代理收到用户信息〗
C. The domain collector agent may perform a DNS lookup for the authenticated client's IP address.〖域收集器代理可能会执行DNS查找认证客户机的IP地址〗
D. The user cannot be authenticated with the FortiGate in this manner because each domain controller agent requires a dedicated collector agent.〖用户不能以这种方式通过FortiGate身份验证,因为每个域控制器代理需要一个专用收集器代理〗
【分析】
收集器代理不一定要安装在域服务器上,它用来接收DC代理发来的登录事件日志,并将登录信息发给FortiGate,DC代理可以有多个,收集器代理只需要一个。
【答案】AC
飞塔技术-老梅子 QQ:57389522