nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #70

Refer to the exhibit, which shows an SSL certification inspection configuration. SSL certification inspection configuration While testing, the administrator updated the ssl-ssh-profile configuration…

The correct answer is B. FortiGate closes the connection because this represents an invalid SSL/TLS header. See the full explanation below for the reasoning.

Question

Refer to the exhibit, which shows an SSL certification inspection configuration. SSL certification inspection configuration While testing, the administrator updated the ssl-ssh-profile configuration with the command set sni-server-cert-check strict. The administrator found that the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. With respect to the set sni-server-cert-check strict command, which action does FortiGate take?

Exhibit

FCSS_EFW_AD-7.4 question #70 exhibit

Options

  • AFortiGate uses the first entry listed in the SAN field in the server certificate.
  • BFortiGate closes the connection because this represents an invalid SSL/TLS header.
  • CFortiGate uses the CN information from the Subject field in the server certificate.
  • DFortiGate uses the SNI from the user's web browser.

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    74% (23)
  • C
    6% (2)
  • D
    13% (4)

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice