nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #54

A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?

The correct answer is B. SSL VPN http-request-header-timeout. The SSL VPN http-request-header-timeout timer is used to mitigate denial of service (DoS) attacks by limiting the amount of time the FortiGate waits for the client to send an HTTP request header after a connection is established. This helps reduce the attack surface by…

VPN

Question

A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?

Options

  • ASSL VPN dcls-hello-timeout
  • BSSL VPN http-request-header-timeout
  • CSSL VPN login-timeout
  • DSSL VPN idle-timeout

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    82% (18)
  • C
    5% (1)
  • D
    5% (1)

Explanation

The SSL VPN http-request-header-timeout timer is used to mitigate denial of service (DoS) attacks by limiting the amount of time the FortiGate waits for the client to send an HTTP request header after a connection is established. This helps reduce the attack surface by preventing potential attacks that exploit prolonged connection times without fully completing requests.

Topics

#SSL VPN#DoS mitigation#http-request-header-timeout#attack surface

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice