An OT supervisor has configured LDAP and FSSO for the authentication. The goal is that all the users be authenticated against passive authentication first and, if passive authentication is not successful, then users should be challenged with active authentication. What should the OT supervisor do to achieve this on FortiGate?

A.    Configure a firewall policy with LDAP users and place it on the top of list of firewall policies.
B.    Enable two-factor authentication with FSSO.
C.    Configure a firewall policy with FSSO users and place it on the top of list of firewall policies.
D.    Under config user settings configure set auth-on-demand implicit.