nerdexam
Fortinet

NSE7_EFW-7.2 · Question #28

Refer to the exhibit, which shows an SSL certification inspection configuration. Which action does FortiGate take if the server name indication (SNI) does not match either the common name (CN) or…

The correct answer is B. FortiGate uses the CN information from the Subject field in the server certificate. If the domain in the SNI field does not match any of the domains listed in the CN and SAN fields, FortiGate uses the domain in the CN field instead of the domain in the SNI field.

FortiGate Security Features

Question

Refer to the exhibit, which shows an SSL certification inspection configuration. Which action does FortiGate take if the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate?

Exhibit

NSE7_EFW-7.2 question #28 exhibit

Options

  • AFortiGate uses the first entry listed in the SAN field in the server certificate
  • BFortiGate uses the CN information from the Subject field in the server certificate
  • CFortiGate uses the SNI from the user's web browser.
  • DFortiGate closes the connection because this represents an invalid SSL/TLS configuration

How the community answered

(49 responses)
  • A
    2% (1)
  • B
    84% (41)
  • C
    6% (3)
  • D
    8% (4)

Explanation

If the domain in the SNI field does not match any of the domains listed in the CN and SAN fields, FortiGate uses the domain in the CN field instead of the domain in the SNI field.

Topics

#SSL inspection#SNI#certificate CN#SAN

Community Discussion

No community discussion yet for this question.

Full NSE7_EFW-7.2 Practice