nerdexam
Fortinet

FCSS_EFW_AD-7.6 · Question #28

A user reports that their computer was infected with malware after accessing a secured HTTPS website. However, when the administrator checks the FortiGate logs, they do not see that the website was…

The correct answer is D. The administrator must enable full SSL inspection in the SSL/SSH Inspection Profile to decrypt. FortiGate, like other security appliances, cannot analyze encrypted HTTPS traffic unless it decrypts it first. If only certificate inspection is enabled, FortiGate can see the certificate details (such as the domain and issuer) but cannot inspect the actual web content. To…

Advanced Threat Protection

Question

A user reports that their computer was infected with malware after accessing a secured HTTPS website. However, when the administrator checks the FortiGate logs, they do not see that the website was detected as insecure despite having an SSL certificate and correct profiles applied on the policy. How can an administrator ensure that FortiGate can analyze encrypted HTTPS traffic on a website?

Options

  • AThe administrator must enable reputable websites to allow only SSL/TLS websites rated by
  • BThe administrator must enable URL extraction from SNI on the SSL certificate inspection to
  • CThe administrator must enable DNS over TLS to protect against fake Server Name Indication
  • DThe administrator must enable full SSL inspection in the SSL/SSH Inspection Profile to decrypt

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    2% (1)
  • D
    91% (42)

Explanation

FortiGate, like other security appliances, cannot analyze encrypted HTTPS traffic unless it decrypts it first. If only certificate inspection is enabled, FortiGate can see the certificate details (such as the domain and issuer) but cannot inspect the actual web content. To fully analyze the traffic and detect potential malware threats: Full SSL inspection (Deep Packet Inspection) must be enabled in the SSL/SSH Inspection Profile. This allows FortiGate to decrypt the HTTPS traffic, inspect the content, and then re-encrypt it before forwarding it to the user. Without full SSL inspection, threats embedded in encrypted traffic may go undetected.

Topics

#full SSL inspection#HTTPS decryption#malware detection#SSL certificate inspection

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.6 Practice