nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #24

Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

The correct answer is B. The server name indication (SNI) extension in the client hello message. C. The subject alternative name (SAN) field in the server certificate. D. The subject field in the server certificate. When SSL certificate inspection is enabled on a FortiGate device, the system uses the following three pieces of information to identify the hostname of the SSL server: Server Name Indication (SNI) extension in the client hello message (B): The SNI is an extension in the client…

Content inspection

Question

Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

Options

  • AThe host field in the HTTP header.
  • BThe server name indication (SNI) extension in the client hello message.
  • CThe subject alternative name (SAN) field in the server certificate.
  • DThe subject field in the server certificate.
  • EThe serial number in the server certificate.

How the community answered

(16 responses)
  • A
    13% (2)
  • B
    81% (13)
  • E
    6% (1)

Explanation

When SSL certificate inspection is enabled on a FortiGate device, the system uses the following three pieces of information to identify the hostname of the SSL server: Server Name Indication (SNI) extension in the client hello message (B): The SNI is an extension in the client hello message of the SSL/TLS protocol. It indicates the hostname the client is attempting to connect to. This allows FortiGate to identify the server's hostname during the SSL Subject Alternative Name (SAN) field in the server certificate (C): The SAN field in the server certificate lists additional hostnames or IP addresses that the certificate is valid for. FortiGate inspects this field to confirm the identity of the server. Subject field in the server certificate (D): The Subject field contains the primary hostname or domain name for which the certificate was issued. FortiGate uses this information to match and validate the server's identity during SSL certificate inspection.

Topics

#SSL certificate inspection#SNI#SAN#server certificate

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice