ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 25 - NSE8_812 discussion

Report
Export

Refer to the exhibits, which show a firewall policy configuration and a network topology.

An administrator has configured an inbound SSL inspection profile on a FortiGate device (FG-1) that is protecting a data center hosting multiple web pages-Given the scenario shown in the exhibits, which certificate will FortiGate use to handle requests to xyz.com?

A.
FortiGate will fall-back to the default Fortinet_CA_SSL certificate.
Answers
A.
FortiGate will fall-back to the default Fortinet_CA_SSL certificate.
B.
FortiGate will reject the connection since no certificate is defined.
Answers
B.
FortiGate will reject the connection since no certificate is defined.
C.
FortiGate will use the Fortinet_CA_Untrusted certificate for the untrusted connection,
Answers
C.
FortiGate will use the Fortinet_CA_Untrusted certificate for the untrusted connection,
D.
FortiGate will use the first certificate in the server-cert list—the abc.com certificate
Answers
D.
FortiGate will use the first certificate in the server-cert list—the abc.com certificate
Suggested answer: A

Explanation:

When using inbound SSL inspection, FortiGate needs to present a certificate to the client that matches the requested domain name. If no matching certificate is found in the server-cert list, FortiGate will fall-back to the default Fortinet_CA_SSL certificate, which is self-signed and may trigger a warning on the client browser. Reference:

https://docs.fortinet.com/document/fortigate/6.4.0/cookbook/103437/inbound-ssl-inspection

asked 18/09/2024
Gennaro Migliaccio
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first