Fortinet
NSE7_EFW-6.2 · Question #107
When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does not provide the server name indication (SNI) extension?
The correct answer is B. FortiGate uses the CN information from the Subject field in the server certificate. See the full explanation below for the reasoning.
Question
When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does not provide the server name indication (SNI) extension?
Options
- AFortiGate uses the requested URL from the user's web browser.
- BFortiGate uses the CN information from the Subject field in the server certificate.
- CFortiGate blocks the request without any further inspection.
- DFortiGate switches to the full SSL inspection method to decrypt the data.
How the community answered
(43 responses)- A14% (6)
- B74% (32)
- C7% (3)
- D5% (2)
Community Discussion
No community discussion yet for this question.