CCFA-200B · Question #69
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
The correct answer is A. Deep packet inspection. The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep pack
Question
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
Options
- ADeep packet inspection
- BLinux Sub-System
- CPowerShell
- DWindows Proxy
How the community answered
(25 responses)- A88% (22)
- B4% (1)
- C8% (2)
Explanation
The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep packet inspection may interfere with the sensor's certificate validation, which is a feature that verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. If the certificate validation fails, the sensor will reject the connection and generate an error.
Topics
Community Discussion
No community discussion yet for this question.