nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #77

A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites…

The correct answer is B. The browser does not trust the certificate used by FortiGate for SSL inspection. When full SSL inspection is enabled, FortiGate intercepts HTTPS traffic, decrypts it for inspection, and re-encrypts it using its own SSL certificate before forwarding it to the browser. If the browser does not trust the SSL certificate being used by FortiGate for…

Content inspection

Question

A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?

Options

  • AThe option invalid SSL certificates is set to allow on the SSL/SSH inspection profile
  • BThe browser does not trust the certificate used by FortiGate for SSL inspection
  • CThe certificate used by FortiGate for SSL inspection does not contain the required certificate
  • DThe matching firewall policy is set to proxy inspection mode

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    84% (31)
  • C
    3% (1)
  • D
    11% (4)

Explanation

When full SSL inspection is enabled, FortiGate intercepts HTTPS traffic, decrypts it for inspection, and re-encrypts it using its own SSL certificate before forwarding it to the browser. If the browser does not trust the SSL certificate being used by FortiGate for re-encryption, it will display certificate warning errors. To resolve this, the certificate used by FortiGate for SSL inspection must be installed and trusted in the browser's certificate store.

Topics

#SSL inspection#certificate trust#HTTPS#web filtering

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice