ExamGecko
Question list
Search
Search

Question 112 - NSE4_FGT-7.2 discussion

Report
Export

A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.

What is the reason for the certificate warning errors?

A.
The matching firewall policy is set to proxy inspection mode.
Answers
A.
The matching firewall policy is set to proxy inspection mode.
B.
The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
Answers
B.
The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
C.
The full SSL inspection feature does not have a valid license.
Answers
C.
The full SSL inspection feature does not have a valid license.
D.
The browser does not trust the certificate used by FortiGate for SSL inspection.
Answers
D.
The browser does not trust the certificate used by FortiGate for SSL inspection.
Suggested answer: D

Explanation:

FortiGate Security 7.2 Study Guide (p.235): 'If FortiGate receives a trusted SSL certificate, then it generates a temporary certificate signed by the built-in Fortinet_CA_SSL certificate and sends it to the browser. If the browser trusts the Fortinet_CA_SSL certificate, the browser completes the SSL handshake. Otherwise, the browser also presents a warning message informing the user that the site is untrusted. In other words, for this function to work as intended, you must import the Fortinet_CA_SSL certificate into the trusted root CA certificate store of your browser.'

asked 18/09/2024
nico farina
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first