FCP_FGT_AD-7.6 · Question #67
You want to ensure that an SSL VPN user's authenticated session does not remain active after they disconnect from the VPN. Which configuration will ensure this?
The correct answer is D. Enable settings to force the firewall authentication session to end when the SSL VPN session. The core problem is that the firewall maintains a separate authentication session that can outlive the SSL VPN session. Enabling a setting that ties the firewall authentication session lifecycle to the SSL VPN session guarantees the authentication session is terminated upon VPN…
Question
You want to ensure that an SSL VPN user’s authenticated session does not remain active after they disconnect from the VPN. Which configuration will ensure this?
Options
- AConfigure the firewall authentication session timeout to be lower than the SSL VPN session
- BManually clear active firewall authentication sessions after a user disconnects.
- CIncrease the SSL VPN idle timeout to reduce the chance of early disconnections.
- DEnable settings to force the firewall authentication session to end when the SSL VPN session
How the community answered
(55 responses)- A2% (1)
- B4% (2)
- C5% (3)
- D89% (49)
Explanation
The core problem is that the firewall maintains a separate authentication session that can outlive the SSL VPN session. Enabling a setting that ties the firewall authentication session lifecycle to the SSL VPN session guarantees the authentication session is terminated upon VPN disconnection, closing the security gap. Lowering the firewall authentication timeout (Option A) reduces the window but does not guarantee immediate termination. Manually clearing sessions (Option B) is a reactive, human-dependent process that is error-prone and not scalable. Increasing the SSL VPN idle timeout (Option C) actually worsens the problem by keeping sessions alive longer. Only Option D provides the direct, automated linkage required.
Topics
Community Discussion
No community discussion yet for this question.