View all questions & answers for the NSE 5 - FortiWeb 8.0 Administrator Exam Materials exam


NSE 5 - FortiWeb 8.0 Administrator Exam Materials-Question 33 Discussion
Comment Image Comment Image Comment Image

You are configuring FortiWeb to handle encrypted HTTPS traffic. You must decide when FortiWeb should terminate SSL and which configuration is required for decryption in each deployment mode. Which two configuration actions correctly implement HTTPS handling on FortiWeb? (Choose two answers)

  • A. Configure server name indication (SNI) routing so FortiWeb selects the correct certificate after it finishes decrypting traffic.
  • B. Install a server certificate on FortiWeb in transparent inspection mode so it can decrypt and inspect HTTPS traffic.
  • C. Configure SSL/TLS offloading so FortiWeb ends the client's HTTPS session and forwards the decrypted traffic to the back-end server.
  • D. Enable an HTTP redirect policy that forces browsers to use HTTPS instead of allowing HSTS to manage the redirect automatically.
Correct Answer: A,C

Brave-Dump Clients Votes

BC 100%

Comments



Fadil Bushra 2026-10-01 06:52:10

Selected Answers: B, C


Why A is wrong ❌
Configure SNI routing so FortiWeb selects the correct certificate after it finishes decrypting traffic.
The problem is "after it finishes decrypting."
SNI is part of the TLS handshake. FortiWeb uses the client's SNI/server name to determine which certificate to present, so this happens during the TLS negotiation, before the encrypted application traffic is decrypted. Fortinet documents SNI as a mechanism for determining which certificate FortiWeb presents based on the domain.
So:
SNI → select certificate → TLS handshake → encryption/decryption
not:
decrypt → SNI → select certificate