ExamGecko
Question list
Search
Search

Question 19 - NSE7_NST-7.2 discussion

Report
Export

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which action will FortiGate take when using the default settings for SSL certificate inspection?

A.
FortiGate closes the connection because this represents an invalid SSL/TLS configuration
Answers
A.
FortiGate closes the connection because this represents an invalid SSL/TLS configuration
B.
FortiGate uses the 31 information from the Subject field in the server certificate.
Answers
B.
FortiGate uses the 31 information from the Subject field in the server certificate.
C.
FortiGate uses the first entry listed in the SAN field in the server certificate.
Answers
C.
FortiGate uses the first entry listed in the SAN field in the server certificate.
D.
FortiGate uses the SNI from the user's web browser.
Answers
D.
FortiGate uses the SNI from the user's web browser.
Suggested answer: A

Explanation:

SNI and Certificate Mismatch: When the Server Name Indication (SNI) does not match either the Common Name (CN) or any of the Subject Alternative Names (SAN) in the server certificate, FortiGate's default behavior is to consider this as an invalid SSL/TLS configuration.

Default Action: FortiGate, under default settings for SSL certificate inspection, will close the connection to prevent potential security risks associated with mismatched certificates.

Fortinet Community: SSL Certificate Inspection Configuration and Behavior (Welcome to the Fortinet Community!).

asked 18/09/2024
ONWUDIWE NYENKE
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first