exam questions

Exam NSE7_ZTA-7.2 All Questions

View all questions & answers for the NSE7_ZTA-7.2 exam

Exam NSE7_ZTA-7.2 topic 1 question 8 discussion

Actual exam question from Fortinet's NSE7_ZTA-7.2
Question #: 8
Topic #: 1
[All NSE7_ZTA-7.2 Questions]

Refer to the exhibits.


Which statement is true about the configuration shown in the exhibit?

  • A. The domain that FortiClient is connecting to should match the domain to which the certificate is issued.
  • B. If the FortiClient EMS server certificate is invalid, FortiClient connects silently.
  • C. The connection from FortiClient to FortiClient EMS uses TCP and TLS 1.2.
  • D. default_ZTNARoot CA signs the FortiClient certificate for the SSL connectivity to FortiClient EMS.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
lil_pc1972
Highly Voted 9 months, 3 weeks ago
FortiClient validates certificates using the following industry standards: • The domain or FQDN that FortiClient is connecting to matches the domain to which the certificate is issued. • The validation process correctly handles wildcards in the domain name in the certificate. • The validation process considers both the CN in the subject or the SAN. • The certificate expiry date is in the future. The certificate has not expired. • The certificate issuer or the root certificate in the certificate chain is from a publicly trusted CA. Trusted CAs are read from the operating system.
upvoted 5 times
...
roderick2389
Most Recent 4 months, 3 weeks ago
Selected Answer: A
A is correct. Domain or fully qualified domain name (FQDN) that FortiClient is connecting to matches the domain to which the certificate is issued.
upvoted 1 times
...
lucient
5 months ago
Selected Answer: A
A is correct. Study Guide page 145: Forticlient validates certificates using the following industry standards: * The domain or FQDN that FortiClient is connecting to matches the domaing to which the certificate is issued. (Also, chech image from page 144). B is wrong. Page 145: If the EMS server certificate is invalid, actions can be configured in Endpoint Profile > System Settings. C is worng. Page 144: The connection from FortiClient to FortiClient EMS uses TCP and TLS 1.3 D is wrong. Page 53 Study Guide: FortiClient EMS has a default_ZTNARootCA certificate generated by default that the ZTNA CA uses to sign CSRs from the FortiClient endpoints. Client certificate information is synchronized with Fortigate and is used for client identity verification.
upvoted 1 times
...
Disposable_Me_2018
7 months ago
Selected Answer: D
Zero Trust Access 7.2 Study Guide page 110: "FortiClient EMS has a default_ZTNARootCA certificate generated by default that the ZTNA CA uses to sign CSRs from the FortiClient endpoints." Answer "D"
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago