View all questions & answers for the NSE 7 - Secure Networking 7.6 Architect Exam Materials exam


NSE 7 - Secure Networking 7.6 Architect Exam Materials-Question 31 Discussion
Comment Image Comment Image Comment Image

You want to harden the SSL/SSH Inspection profile for access to HTTPS web servers. Which two configuration changes allow you to remove vulnerabilities? (Choose two answers)

  • A. Set unsupported-ssl-version to block.
  • B. Set Server certificate SNI check to Enable.
  • C. Set Untrusted SSL certificates to Ignore.
  • D. Set min-allowed-ssl-version to ssl-3.0
Correct Answer: A,B

Brave-Dump Clients Votes

AB 100%

Comments



Brave-Dumps.com Admin 2026-07-19 17:57:17

Selected Answers: A, B


A
FortiGate blocks sessions that use an unsupported SSL/TLS version instead of bypassing inspection.

B
FortiGate compares the SNI from the ClientHello message with the certificate’s CN or SAN fields, helping detect certificate and hostname mismatches.