CCFA-200B · Question #42
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
The correct answer is B. Some network configurations, such as deep packet inspection, interfere with certificate validation. The statement that some network configurations, such as deep packet inspection, interfere with certificate validation is true concerning Falcon sensor certificate validation. The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks, which means that
Question
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
Options
- ASSL inspection should be configured to occur on all Falcon traffic
- BSome network configurations, such as deep packet inspection, interfere with certificate validation
- CHTTPS interception should be enabled to proceed with certificate validation
- DCommon sources of interference with certificate pinning include protocol race conditions and
How the community answered
(48 responses)- A4% (2)
- B88% (42)
- C6% (3)
- D2% (1)
Explanation
The statement that some network configurations, such as deep packet inspection, interfere with certificate validation is true concerning Falcon sensor certificate validation. The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks, which means that it verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. Some network configurations, such as deep packet inspection, SSL inspection, or HTTPS interception, may attempt to modify or replace the server certificate, which will cause the sensor to reject the connection and generate an error.
Topics
Community Discussion
No community discussion yet for this question.