View all questions & answers for the NSE 8 - Written (NSE8_812) Exam Materials exam
Question 89 Discussion
Comments
Selected Answers: B, C
Selected Answers: B, D
→ Si le serveur OCSP est inaccessible, l’authentification échoue (donc C serait normalement faux).
En mode strict, FortiGate ne fait pas de fallback sur la CA.
Si strict-ocsp-check était désactivé, alors C serait vrai (authentification réussit si le certificat correspond à la CA).
Mais ici, il est activé.
Donc, selon la configuration affichée, les bonnes réponses sont B et D.
Selected Answers: C, D
Selected Answers: B, D
An administrator has configured a FortiGate device to authenticate SSL VPN users using dogotal certificates. A FortiAuthenticator is the certificate authority (CA) and the Online Certificate Status Protocol (OCSP) server. Part of the FortiGate configuration is shown below: Based on this configuration, which two statements are true? (Choose two answers)
Brave-Dump Clients Votes