NSE4 · Question #527
Which of the following actions can be used to back up the keys and digital certificates in a FortiGate device? (Choose two.)
The correct answer is A. Taking a full backup of the FortiGate configuration D. Uploading a PKCS#12 file to a TFTP server. FortiGate keys and digital certificates can be backed up either by taking a full device configuration backup or by exporting them as a PKCS#12 file to an external server.
Question
Which of the following actions can be used to back up the keys and digital certificates in a FortiGate device? (Choose two.)
Options
- ATaking a full backup of the FortiGate configuration
- BUploading a PKCS#10 file to a USB drive
- CManually uploading the certificate information to a Certificate authority (CA)
- DUploading a PKCS#12 file to a TFTP server
How the community answered
(46 responses)- A93% (43)
- B4% (2)
- C2% (1)
Why each option
FortiGate keys and digital certificates can be backed up either by taking a full device configuration backup or by exporting them as a PKCS#12 file to an external server.
A full FortiGate configuration backup includes all system settings, including locally stored keys and digital certificates, allowing for restoration of the device's cryptographic identity.
A PKCS#10 file is a certificate signing request (CSR) and contains only the public key, not the private key or the full certificate, making it unsuitable for backup.
Uploading certificate information to a CA is part of the certificate issuance or renewal process, not a method for backing up existing certificates and keys from the FortiGate.
Exporting certificates and their private keys in PKCS#12 format is a standard method for securely backing up cryptographic assets, often to an external storage like a TFTP server.
Concept tested: FortiGate certificate and key backup methods
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526725/backing-up-and-restoring-configuration-files
Topics
Community Discussion
No community discussion yet for this question.