nse7_efw-72 Exam QuestionsBrowse all questions from this exam

nse7_efw-72 Exam - Question 28


Refer to the exhibit, which shows an SSL certification inspection configuration.

Which action does FortiGate take if the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate?

Show Answer
Correct Answer: BD

If the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate, FortiGate uses the CN information from the Subject field in the server certificate. This allows FortiGate to continue the SSL/TLS handshake using the CN, ensuring the continuity of the connection even when there is a mismatch with the SNI.

Discussion

7 comments
Sign in to comment
33k_Option: B
Feb 27, 2024

If the domain in the SNI field does not match any of the domains listed in the CN and SAN fields, FortiGate uses the domain in the CN field instead of the domain in the SNI field.

MikeSco001Option: B
Feb 24, 2024

answer is B : Enterprise_Firewall_7.2_Study_Guide-Online.pdf / p 238

truserudOption: B
Mar 11, 2024

The Correct answer i B as detailed on page 238 in the Study Guide.

5deee77Option: B
Mar 1, 2024

study guide page 238

Kop01Option: B
Mar 4, 2024

Answer B p238

DaLoGoOption: D
Apr 13, 2024

D is correct. Read the question. CN does not match.

charrucoOption: B
Apr 24, 2024

B is correct Study Guide p238