exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 2 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 2
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

  • A. The host field in the HTTP header.
  • B. The server name indication (SNI) extension in the client hello message.
  • C. The subject alternative name (SAN) field in the server certificate.
  • D. The subject field in the server certificate.
  • E. The serial number in the server certificate.
Show Suggested Answer Hide Answer
Suggested Answer: BCD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rigonet
3 weeks, 1 day ago
Selected Answer: BCD
Correct Answers: B. The server name indication (SNI) extension in the client hello message. C. The subject alternative name (SAN) field in the server certificate. D. The subject field in the server certificate. Key Points: B: SNI identifies the hostname in the TLS handshake. C: SAN field specifies the hostname in the certificate. D: Subject field may also contain the hostname. A and E: Not relevant for hostname identification.
upvoted 2 times
...
sxcap
1 month, 1 week ago
Selected Answer: BCD
SNI Subject in the certificate Subject alternative name in the certificate
upvoted 2 times
...
vuhidus
1 month, 2 weeks ago
Selected Answer: BCD
B C D are correct
upvoted 2 times
...
s4mu3l007
2 months ago
BCD are correct
upvoted 2 times
...
hassan76
2 months, 1 week ago
FortiGate_7.4_Administrator_Study_Guide 166
upvoted 2 times
...
miguelmagr
3 months, 1 week ago
B,C,D - Related to Training Fortigate Administrator - Certificate Operations: When using SSL certificate inspection, FortiGate is not decrypting the traffic. During the exchange of hello messages at the beginning of an SSL handshake, FortiGate parses the server name indication (SNI) from client Hello, which is an extension of the TLS protocol. The SNI tells FortiGate the hostname of the SSL server, which is validated against the DNS name before receipt of the server certificate. If there is no SNI exchanged, then FortiGate identifies the server by the value in the server by the value in the Subject field or SAN (Subject Alternative Name) field in the server certificate.
upvoted 3 times
...
gimy19
3 months, 2 weeks ago
B,C,D are correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago