View all questions & answers for the NSE 7 - Secure Networking 7.6 Architect Exam Materials exam
NSE 7 - Secure Networking 7.6 Architect Exam Materials-Question 31 Discussion
Comments
Selected Answers: A, B
FortiGate blocks sessions that use an unsupported SSL/TLS version instead of bypassing inspection.
B
FortiGate compares the SNI from the ClientHello message with the certificate’s CN or SAN fields, helping detect certificate and hostname mismatches.
You want to harden the SSL/SSH Inspection profile for access to HTTPS web servers. Which two configuration changes allow you to remove vulnerabilities? (Choose two answers)
Brave-Dump Clients Votes