nerdexam
Fortinet

NSE7_EFW-6.2 · Question #107

When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does not provide the server name indication (SNI) extension?

The correct answer is B. FortiGate uses the CN information from the Subject field in the server certificate. See the full explanation below for the reasoning.

Question

When using the SSL certificate inspection method to inspect HTTPS traffic, how does FortiGate filter web requests when the client browser does not provide the server name indication (SNI) extension?

Options

  • AFortiGate uses the requested URL from the user's web browser.
  • BFortiGate uses the CN information from the Subject field in the server certificate.
  • CFortiGate blocks the request without any further inspection.
  • DFortiGate switches to the full SSL inspection method to decrypt the data.

How the community answered

(43 responses)
  • A
    14% (6)
  • B
    74% (32)
  • C
    7% (3)
  • D
    5% (2)

Community Discussion

No community discussion yet for this question.

Full NSE7_EFW-6.2 Practice