ExamGecko
Question list
Search
Search

Related questions











Question 134 - 300-730 discussion

Report
Export

Why must a network engineer avoid usage of the default X.509 certificate when implementing clientless SSLVPN on an ASA?

A.

The certificate must be managed by the local CA.

Answers
A.

The certificate must be managed by the local CA.

B.

The certificate is regenerated at each reboot.

Answers
B.

The certificate is regenerated at each reboot.

C.

The default X.509 certificate is not supported for SSLVPN.

Answers
C.

The default X.509 certificate is not supported for SSLVPN.

D.

The certificate is too weak to provide adequate security.

Answers
D.

The certificate is too weak to provide adequate security.

Suggested answer: B

Explanation:

By default, the ASA generates a self-signed X.509 certificate upon startup. This certificate is used in order to serve client connections by default. It is not recommended to use this certificate because its authenticity cannot be verified by the browser. Furthermore, this certificate is regenerated upon each reboot so it changes after each reboot. https://www.cisco.com/c/en/us/support/docs/securityvpn/ webvpn-ssl-vpn/119417-config-asa-00.html

asked 10/10/2024
Tyler Raymond
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first