FCSS_EFW_AD-7.4 · Question #5
A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server. What can the…
The correct answer is A. Configure the unsupported SSL version and set the minimum allowed SSL version in the. The best way to block outdated SSL/TLS versions is to configure the SSL/SSH inspection profile to enforce a minimum SSL/TLS version and disable weak SSL versions. By setting the minimum allowed SSL version in the HTTPS settings of the SSL/SSH inspection profile, FortiGate will…
Question
A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server. What can the firewall administrator do to block all outdated SSL/TLS versions on any HTTPS web server to prevent possible attacks on user traffic?
Options
- AConfigure the unsupported SSL version and set the minimum allowed SSL version in the
- BEnable auto-detection of outdated SSL/TLS versions in the SSL/SSH inspection profile to
- CInstall the required certificate in the client's browser or use Active Directory policies to block
- DUse the latest certificate, Fortinet_SSL_ECDSA256, and replace the CA certificate in the
How the community answered
(35 responses)- A71% (25)
- B6% (2)
- C6% (2)
- D17% (6)
Explanation
The best way to block outdated SSL/TLS versions is to configure the SSL/SSH inspection profile to enforce a minimum SSL/TLS version and disable weak SSL versions. By setting the minimum allowed SSL version in the HTTPS settings of the SSL/SSH inspection profile, FortiGate will: Block any connection using outdated SSL/TLS versions (such as SSLv3, TLS 1.0, or TLS 1.1). Enforce secure communication using only strong SSL/TLS versions (such as TLS 1.2 or TLS 1.3). Protect users from man-in-the-middle (MITM) and downgrade attacks that exploit weak
Topics
Community Discussion
No community discussion yet for this question.