nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #42

Refer to the exhibit. What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

The correct answer is C. FortiGate will close the connection if the SNI does not match the CN or SAN fields. SNI-server-cert-check Enable: Check the SNI in the client hello message with the CN or SAN fields in the returned server certificate. If mismatched, use the CN in the server certificate to do URL filtering. Strict: Check the SNI in the client hello message with the CN or SAN…

Submitted by klara.se· Apr 18, 2026Content inspection

Question

Refer to the exhibit. What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

Exhibit

FCP_FGT_AD-7.6 question #42 exhibit

Options

  • AFortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not
  • BFortiGate will accept the connection with a warning if the SNI does not match the CN or SAN
  • CFortiGate will close the connection if the SNI does not match the CN or SAN fields.
  • DFortiGate will close the connection if the SNI does not match the CN and SAN fields

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    88% (36)
  • D
    2% (1)

Explanation

SNI-server-cert-check Enable: Check the SNI in the client hello message with the CN or SAN fields in the returned server certificate. If mismatched, use the CN in the server certificate to do URL filtering. Strict: Check the SNI in the client hello message with the CN or SAN fields in the returned server certificate. If mismatched, close the connection. Disable: Do not check the SNI in the client hello message with the CN or SAN fields in the returned server certificate.

Topics

#SSL Inspection#SNI#Certificate Validation#Connection Enforcement

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice