exam questions

Exam NSE8_812 All Questions

View all questions & answers for the NSE8_812 exam

Exam NSE8_812 topic 1 question 49 discussion

Actual exam question from Fortinet's NSE8_812
Question #: 49
Topic #: 1
[All NSE8_812 Questions]

An administrator has configured a FortiGate device to authenticate SSL VPN users using dogotal certificates. A FortiAuthenticator is the certificate authority (CA) and the Online Certificate Status Protocol (OCSP) server.
Part of the FortiGate configuration is shown below:

Based on this configuration, which two statements are true? (Choose two.)

  • A. OCSP checks will always go to the configured FortiAuthenticator
  • B. The OCSP check of the certificate can be combined with a certificate revocation list
  • C. OCSP certificate responses are never cached by the FortiGate
  • D. If the OCSP server is unreachable, authentication will succeed if the certificate matches the CA
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kinge2
4 months, 1 week ago
Selected Answer: AC
https://help.fortinet.com/fadc/4-4-0/cli/Content/FortiADC/cli-ref/config_system_certificate_crl.htm Online certificate status protocol (OCSP) is an alternative to CRL. OCSP is useful when you do not want to deploy CRL files, for example, or want to avoid the public exposure of your PKI structure even if it is only invalid certificates. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-OCSP-and-OSCP-responder-errors/ta-p/198293 Certificate Revocation Lists are cached lists that contain the validity of certificates. There can be a change in the validity of the certificate, however, the cached CRL would not have that information. OCSP avoids that problem by sending on-demand requests to an OCSP server to confirm a certificate’s validity.
upvoted 1 times
...
node345
10 months, 2 weeks ago
Selected Answer: AB
I vote for A and B. A is correct because of the ocsp-default-server setting and because the CA for the configured peer is also the FortiAuthenticator. Otherwise it would not be correct because we have "ocsp-option certificate". B is also correct because you can configure CRL and OCSP checking independently. C is tricky, but probably not correct, because I found a bug in FortiOS with the following description "534346 WAD memory leak on OCSP certificate caching", which means that there is some OCSP caching. D is not correct because of the setting "set strict-ocsp-check enable".
upvoted 1 times
...
ac89l
11 months, 3 weeks ago
Selected Answer: AB
i vote for AB
upvoted 2 times
ac89l
11 months, 3 weeks ago
correction: AC C- Certificate Revocation Lists are cached lists that contain the validity of certificates. There can be a change in the validity of the certificate, however, the cached CRL would not have that information. OCSP avoids that problem by sending on-demand requests to an OCSP server to confirm a certificate’s validity. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-OCSP-and-OSCP-responder-errors/ta-p/198293
upvoted 1 times
MightyPirateC
2 months, 3 weeks ago
In that document, there is "OCSP enables applications to determine the revocation status of digital certificates instead of (or as a supplement) checking a periodic CRL". So B MUST be correct. About A, we all agree. So, as only two answers can be correct, it must be AB.
upvoted 1 times
...
ac89l
11 months, 3 weeks ago
reviewing the question for the third time >> such a stupid misleading question
upvoted 1 times
...
...
...
ama6
1 year, 3 months ago
A. OCSP checks will always go to the configured FortiAuthenticator: This statement is true. The configuration specifies "Set ocsp-default-server Fortiauthenticator," which means that OCSP checks will always be directed to the configured FortiAuthenticator server for certificate status verification.
upvoted 1 times
...
ama6
1 year, 3 months ago
B and D Are Correct Certificate Revocation Lists (CRLs) | FortiGate / FortiOS 7.2.0 - Fortinet Document Library Online Certificate Status Protocol (OCSP) | FortiGate / FortiOS 7.2.0 - Fortinet Document Library
upvoted 1 times
ac89l
11 months, 3 weeks ago
How is could be D correct when you have strict-ocsp-check ?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago