Join the discussion
Question 27/61
Which Fortinet solution can you integrate FortiClient with to use the single sign-on mobility agent (SSOMA) feature? (Choose one answer)
Correct Answer: A
According to theFortiClient EMS 7.2/7.4 Administration GuideandFortiAuthenticator Study Guides, the Single Sign-On Mobility Agent (SSOMA)is a feature specifically designed to integrate with FortiAuthenticatorto provide transparent, identity-based authentication.
1. Integration with FortiAuthenticator (Answer A)
* The SSOMA Service:The mobility agent service is hosted on theFortiAuthenticatorunit.
Administrators must navigate toFortinet SSO Methods > SSO > Generalon the FortiAuthenticator and toggle onEnable FortiClient SSO Mobility Agent Service.
* Communication Protocol:FortiClient communicates with FortiAuthenticator via a specified TCP listening port (defaulting to8001or8005) and uses apre-shared key(secret key) for authentication.
* Transparent Authentication:Once configured, the SSOMA on the endpoint automatically sends user logon information and IP address changes (such as WiFi roaming) to FortiAuthenticator.
FortiAuthenticator then shares this information with FortiGate units to enforce identity-based security policies without the user needing to re-authenticate manually.
2. Modern Capabilities (Azure AD / Entra ID)
* Cloud Integration:In FortiClient 7.2.1 and later, SSOMA supportsnative Azure AD (Entra ID). In this mode, the agent sends the Azure AD domain and tenant ID directly to FortiAuthenticator, allowing organizations to create identity-based policies for cloud-joined devices.
3. Note on FortiPAM (Option C)
* Recent Updates:While recent FortiClient EMS 7.4 documentation mentions an"Add FortiPAM agent to SSOMA"feature, this is an extension of the existing SSOMA framework. The core product that defines and runs the SSOMA service for general Single Sign-On (SSO) remainsFortiAuthenticator.
4. Why Other Options are Incorrect
* B. FortiSASE:While FortiSASE uses FortiClient for Secure Internet Access (SIA), it uses different mechanisms (like SAML or the SASE cloud portal) for user identity rather than the specific SSOMA agent service.
* D. FortiNAC:FortiNAC uses FortiClient for persistent agent-based posture assessment and scanning, but it does not utilize the SSOMA mobility agent for user-to-IP mapping.
1. Integration with FortiAuthenticator (Answer A)
* The SSOMA Service:The mobility agent service is hosted on theFortiAuthenticatorunit.
Administrators must navigate toFortinet SSO Methods > SSO > Generalon the FortiAuthenticator and toggle onEnable FortiClient SSO Mobility Agent Service.
* Communication Protocol:FortiClient communicates with FortiAuthenticator via a specified TCP listening port (defaulting to8001or8005) and uses apre-shared key(secret key) for authentication.
* Transparent Authentication:Once configured, the SSOMA on the endpoint automatically sends user logon information and IP address changes (such as WiFi roaming) to FortiAuthenticator.
FortiAuthenticator then shares this information with FortiGate units to enforce identity-based security policies without the user needing to re-authenticate manually.
2. Modern Capabilities (Azure AD / Entra ID)
* Cloud Integration:In FortiClient 7.2.1 and later, SSOMA supportsnative Azure AD (Entra ID). In this mode, the agent sends the Azure AD domain and tenant ID directly to FortiAuthenticator, allowing organizations to create identity-based policies for cloud-joined devices.
3. Note on FortiPAM (Option C)
* Recent Updates:While recent FortiClient EMS 7.4 documentation mentions an"Add FortiPAM agent to SSOMA"feature, this is an extension of the existing SSOMA framework. The core product that defines and runs the SSOMA service for general Single Sign-On (SSO) remainsFortiAuthenticator.
4. Why Other Options are Incorrect
* B. FortiSASE:While FortiSASE uses FortiClient for Secure Internet Access (SIA), it uses different mechanisms (like SAML or the SASE cloud portal) for user identity rather than the specific SSOMA agent service.
* D. FortiNAC:FortiNAC uses FortiClient for persistent agent-based posture assessment and scanning, but it does not utilize the SSOMA mobility agent for user-to-IP mapping.
Add Comments
- Other Question (61q)
- Q1. Which component or device shares device status information through ZTNA telemetry?...
- Q2. Which two statements are true about the ZTNA rule? (Choose two.)...
- Q3. Refer to the exhibit, which shows the Zero Trust Tagging Rule Set configuration. (Exhibit)...
- Q4. Refer to the exhibit. (Exhibit) Based on The settings shown in The exhibit, which statemen...
- Q5. Which two statements are true about ZTNA? {Choose two.)...
- Q6. FortiGate devices in the Security Fabric must receive endpoint from the FortiClient EMS fo...
- Q7. Which component or device defines ZTNA lag information in the Security Fabric integration?...
- Q8. An administrator is required to maintain a software vulnerability on the endpoints, withou...
- Q9. What does FortiClient do as a fabric agent? (Choose two.)...
- Q10. Which statement about the FortiClient enterprise management server is true?...
- Q11. In a ForliSandbox integration, what does the remediation option do?...
- Q12. Refer to the exhibits. Based on the FortiGate Security Fabric settings shown in the exhibi...
- Q13. Refer to the exhibit. (Exhibit) Based on the FortiClient logs shown in the exhibit which a...
- Q14. Which statement about deploying FortiClient EMS in an air-gapped environment is true?...
- Q15. An administrator has a requirement to add user authentication to the ZTNA access for remot...
- Q16. Based on the logs shown in the exhibit, why did FortiClient EMS fail to install FortiClien...
- Q17. Refer to the exhibits. How will the vulnerability shown in the scan be patched? (Exhibit)...
- Q18. Refer to the exhibit. FortiGate has lost connectivity with FortiClient EMS. What is causin...
- Q19. In a FortiClient EMS deployment, what is the primary security function of the endpoint con...
- Q20. Refer to the exhibit. Based on the settings shown in the exhibit, which two actions must t...
- Q21. Refer to the exhibit. (Exhibit) Based on the settings shown in the exhibit, which two acti...
- Q22. An administrator deploys a FortiClient installation through the Microsoft AD group policy ...
- Q23. A FortiClient EMS administrator has enabled the compliance rule for the sales department W...
- Q24. Which security attribute is verified during the SSL connection negotiation between FortiCl...
- Q25. An administrator needs to connect FortiClient EMS as a fabric connector to FortiGate What ...
- Q26. Exhibit. (Exhibit) Based on the FortiClient logs shown in the exhibit, which endpoint prof...
- Q27. Which Fortinet solution can you integrate FortiClient with to use the single sign-on mobil...
- Q28. Which statement about FortiClient enterprise management server is true?...
- Q29. Refer to the exhibit, which shows FortiClient EMS deployment, profiles. (Exhibit) When an ...
- Q30. Refer to the exhibit. (Exhibit) Based on the settings shown in the exhibit what action wil...
- Q31. Refer to the exhibit. Based on the Security Fabric automation settings, what action will b...
- Q32. What does FortiClient do as a fabric agent? (Choose two.)...
- Q33. Which two statements about FortiClient EMS integration with Active Directory (AD) are true...
- Q34. An administrator configures ZTNA configuration on the FortiGate. Which statement is true a...
- Q35. Refer to the exhibit. (Exhibit) The zero trust network access (ZTNA) serial number on endp...
- Q36. An administrator must deploy FortiClient for an organization that has BYOD and remote user...
- Q37. Which three types of antivirus scans are available on FortiClient? (Choose three )...
- Q38. Which statement about FortiClient enterprise management server is true?...
- Q39. Refer to the exhibit. Based on the settings shown in the exhibit, which statement about Fo...
- Q40. Which two VPN types can a FortiClient endpoint user inmate from the Windows command prompt...
- Q41. Which two statements about ZTNA destinations are true? (Choose two.)...
- Q42. Refer to the exhibit. You provide a webserver hosting service. An endpoint downloads a tes...
- Q43. Which of the following overrides site categories action in FortiClient web-filter?...
- Q44. A security architect has designed a high availability (HA) solution with three FortiClient...
- Q45. A FortiClient EMS administrator has created multiple deployment configurations, and the en...
- Q46. Refer to the exhibit. (Exhibit) Why is the user not able to access bbc.com? (Choose one an...
- Q47. Which two VPNtypes can a FortiClientendpoint user inmate from the Windows command prompt? ...
- Q48. Which statement about the FortiClient enterprise management server is true?...
- Q49. Refer to the exhibit. The zero trust network access (ZTNA) serial number on endpoint br-pc...
- Q50. Which statement about the FortiClient EMS console logs is true?...
- Q51. Refer to the exhibit. An administrator has restored the modified XML configuration file to...
- Q52. Refer to the exhibit, which shows FortiClient EMS deployment, profiles. (Exhibit) When an ...
- Q53. A FortiClient EMS administrator is implementing additional security on FortiClient for com...
- Q54. Which two statements are true about the ZTNA rule? (Choose two.)...
- Q55. An administrator is required to maintain a software vulnerability on the endpoints, withou...
- Q56. An administrator must add an authentication server on FortiClient EMS in a different secur...
- Q57. Which Fortinet solution can you integrate FortiClient with to use the single sign-on mobil...
- Q58. A FortiClient EMS administrator has enabled the compliance rule for the sales department W...
- Q59. Refer to the exhibit. (Exhibit) Based on the settings shown in the exhibit, which action w...
- Q60. An administrator needs to connect FortiClient EMS as a fabric connector to FortiGate What ...
- Q61. Refer to the exhibit. Based on the CLI output from FortiGate. which statement is true? (Ex...
[×]
Download PDF File
Enter your email address to download Fortinet.FCP_FCT_AD-7.4.v2026-08-31.q61.pdf
