nse7_zta-72 Exam QuestionsBrowse all questions from this exam

nse7_zta-72 Exam - Question 30


Which two statements are true regarding certificate-based authentication for ZTNA deployment? (Choose two.)

Show Answer
Correct Answer: BCD

For a ZTNA deployment, the default action for empty certificates is to block, and this setting can be adjusted using the FortiGate CLI. This indicates that certainly, the certificate-related actions can be managed through the CLI, confirming option C. Therefore, options B and C are correct.

Discussion

4 comments
Sign in to comment
kfaebuOptions: BC
May 5, 2024

By default client certificate authentication is enabled on the access proxy and it block the traffic if the client certificate is empty, You can change the action using the CLI, if required. Study Page 118 i think its BC

Disposable_Me_2018Options: BD
Jun 10, 2024

Zero Trust Access 7.2 Study Guide p118 "By default, client certificate authentication is enabled on the access proxy policy and it blocks the traffic if the client certificate is empty. You can change the action using the CLI, if required." B is correct D is correct A is wrong I think C is wrong due to the wording implying that all certificate actions can only be configured on the GUI.

Disposable_Me_2018
Jun 13, 2024

Correction. I meant "... on the CLI"

saulcastellanos8Options: BD
Apr 7, 2024

By default client certificate authentication is enabled on the access proxy and it block the traffic if the client certificate is empty

Fikachew
Apr 9, 2024

Study guide page 118: By default client certificate authentication is enabled on the access proxy and it block the traffic if the client certificate is empty. You can change the action using the CLI, if required. Could be both BC, BD and CD...