How can you ensure FortiGate can analyze encrypted HTTPS traffic?
A.
Enable SNI
B.
Enable full SSL inspection
C.
Set TLS 1.2
D.
Enable proxy
The Answer Is:
B
This question includes an explanation.
Explanation:
According to the FortiGate security profile documentation, standard certificate inspection (which uses SNI) only examines the certificate header and does not allow the firewall to see the actual payload of an encrypted session. To identify attacks such as PHP code injection or malware hidden within HTTPS traffic, the FortiGate must be configured with full SSL inspection (also known as deep SSL inspection). This process requires the FortiGate to act as a man-in-the-middle, decrypting the traffic using a trusted CA certificate, inspecting the cleartext content for threats, and then re-encrypting it before sending it to the destination.
==============
FCSS_EFW_AD-7.6 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"