ExamGecko
Question list
Search
Search

List of questions

Search

Question 47 - NSE5_FCT-7.0 discussion

Report
Export

Refer to the exhibits, which show a network topology diagram of ZTNA proxy access and the ZTNA rule configuration.

An administrator runs the diagnose endpoint record list CLI command on FortiGate to check Remote-Client endpoint information, however Remote-Client is not showing up in the endpoint record list.

What is the cause of this issue?

A.
Remote-Client failed the client certificate authentication.
Answers
A.
Remote-Client failed the client certificate authentication.
B.
Remote-Client provided an empty client certificate to connect to the ZTNA access proxy.
Answers
B.
Remote-Client provided an empty client certificate to connect to the ZTNA access proxy.
C.
Remote-Client has not initiated a connection to the ZTNA access proxy.
Answers
C.
Remote-Client has not initiated a connection to the ZTNA access proxy.
D.
Remote-Client provided an invalid certificate to connect to the ZTNA access proxy.
Answers
D.
Remote-Client provided an invalid certificate to connect to the ZTNA access proxy.
Suggested answer: A

Explanation:

'You can use CLI Command [...] to verify the presence of matching endpoint record [...] If any of the Information is missing or incomplete, client certificate authentication might fail because FortiClient cannot locate corresponding endpoint entry.' There is probably a typo there and it should read: 'because FortiGate cannot locate corresponding endpoint entry.' --> see Admin guide for 'endpoint record list' and CLI command in that context. https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/25915/establish-device-identity-and-trust-context-with-forticlient-ems

asked 18/09/2024
Preety Koul
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first