ExamGecko
Question list
Search
Search

Question 15 - NSE7_NST-7.2 discussion

Report
Export

Refer to the exhibit, which shows the output of a real-time debug.

Which statement about this output is true?

A.
The server hostname was extracted from the SNI in the client request, or from the CN in the server certificate
Answers
A.
The server hostname was extracted from the SNI in the client request, or from the CN in the server certificate
B.
FortiGate found the requested URL in its local cache.
Answers
B.
FortiGate found the requested URL in its local cache.
C.
This web request was inspected using the rtgd-allow web filter profile.
Answers
C.
This web request was inspected using the rtgd-allow web filter profile.
D.
The requested URL belongs to category ID 255.
Answers
D.
The requested URL belongs to category ID 255.
Suggested answer: A

Explanation:

The exhibit displays the output of a real-time debug of the URL filtering process on a FortiGate device. The debug output includes various details about a web request being processed.

SNI (Server Name Indication): This is part of the SSL/TLS handshake where the client specifies the hostname it is trying to connect to. FortiGate can use this information to apply appropriate web filtering rules based on the server name.

CN (Common Name): This is a field in the server's SSL certificate that typically contains the server's hostname. FortiGate can extract this information to verify the identity of the server and apply security policies accordingly.

Given that the debug output includes the hostname 'training.fortinet.com,' it is likely derived from the SNI in the client's request or the CN in the server's certificate, indicating that FortiGate is using this information to process the web request.

Fortinet Community Documentation on Real-time Debugging

asked 18/09/2024
Arlind Tereziu
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first