nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #30

Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud. What two conclusions can you draw from the exhibit? (Choose two.)

The correct answer is D. The wildcard for the domain *.fortinet-ca2.support.fortinet.com must be supported by. The packet capture output displays a TLS Client Hello message from FortiGate to FortiManager Cloud. This message contains Server Name Indication (SNI), which is used to indicate the domain name that FortiGate is trying to connect to. FortiGate will receive a certificate that…

System and Network Configuration

Question

Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud. What two conclusions can you draw from the exhibit? (Choose two.)

Exhibit

FCSS_EFW_AD-7.4 question #30 exhibit

Options

  • AFortiGate will receive a certificate that supports multiple domains because FortiManager
  • BFortiGate is connecting to the same IP server and will receive an independent certificate for its
  • CIf the TLS handshake contains 17 cipher suites it means the TLS version must be 1.0 on this
  • DThe wildcard for the domain *.fortinet-ca2.support.fortinet.com must be supported by

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    14% (5)
  • C
    9% (3)
  • D
    74% (26)

Explanation

The packet capture output displays a TLS Client Hello message from FortiGate to FortiManager Cloud. This message contains Server Name Indication (SNI), which is used to indicate the domain name that FortiGate is trying to connect to. FortiGate will receive a certificate that supports multiple domains because FortiManager operates in a cloud computing environment. FortiManager Cloud hosts multiple customers and domains under a shared infrastructure. The TLS handshake includes SNI (Server Name Indication), which allows FortiManager Cloud to serve multiple certificates based on the requested domain. This means FortiGate will likely receive a multi-domain or wildcard certificate that can be used for multiple customers under FortiManager Cloud. The wildcard for the domain .fortinet-ca2.support.fortinet.com must be supported by FortiManager The SNI extension contains the domain 9398.support.fortinet-ca2.fortinet.com. FortiManager Cloud must support wildcard certificates such as *.fortinet-ca2.support.fortinet.com to securely manage multiple subdomains and customers. This ensures that FortiGate can validate the server certificate without any TLS errors.

Topics

#TLS handshake#wildcard certificate#FortiManager Cloud#packet capture analysis

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice