Fortinet
FCP_FGT_AD-7.6 · Question #94
A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?
The correct answer is A. SSL VPN http-request-header-timeout. config vpn ssl settings set http-request-header-timeout <1-60> Timers can also help to mitigate DoS attacks with SSL VPN caused by partial HTTP requests.
Submitted by akirajp· Apr 18, 2026VPN
Question
A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?
Options
- ASSL VPN http-request-header-timeout
- BSSL VPN dtls-hello-timeout
- CSSL VPN login-timeout
- DSSL VPN idle-timeout
How the community answered
(42 responses)- A69% (29)
- B17% (7)
- C5% (2)
- D10% (4)
Explanation
config vpn ssl settings set http-request-header-timeout <1-60> Timers can also help to mitigate DoS attacks with SSL VPN caused by partial HTTP requests.
Topics
#SSL VPN#DoS Mitigation#Security Hardening#FortiGate Configuration
Community Discussion
No community discussion yet for this question.