NSE4 · Question #56
When the SSL proxy is NOT doing man-in-the-middle interception of SSL traffic, which certificate field can be used to determine the rating of a website?
The correct answer is B. Common Name. When SSL proxy is not performing man-in-the-middle interception, the FortiGate can still determine a website's rating by inspecting the Common Name (CN) field in the server's certificate during the SSL handshake.
Question
When the SSL proxy is NOT doing man-in-the-middle interception of SSL traffic, which certificate field can be used to determine the rating of a website?
Options
- AOrganizational Unit.
- BCommon Name.
- CSerial Number.
- DValidity.
How the community answered
(44 responses)- A7% (3)
- B89% (39)
- C2% (1)
- D2% (1)
Why each option
When SSL proxy is not performing man-in-the-middle interception, the FortiGate can still determine a website's rating by inspecting the Common Name (CN) field in the server's certificate during the SSL handshake.
The Organizational Unit field identifies a specific department or division within an organization and provides no information about the website's domain or content rating.
During an SSL handshake, even without full man-in-the-middle decryption, the FortiGate can read the server's certificate, and the Common Name (CN) field typically contains the Fully Qualified Domain Name (FQDN) of the website, which is used for web filtering lookups.
The Serial Number is a unique identifier for the certificate itself, issued by the Certificate Authority, and provides no information about the website's content or category.
Validity refers to the period during which the certificate is considered valid, which is irrelevant to the website's content rating.
Concept tested: SSL inspection and web filtering without MITM
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/993781/ssl-ssh-inspection
Topics
Community Discussion
No community discussion yet for this question.