exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 13 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 13
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate.
Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choose three.)

  • A. Allow & Warning
  • B. Trust & Allow
  • C. Allow
  • D. Block & Warning
  • E. Block
Show Suggested Answer Hide Answer
Suggested Answer: BCE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IBB90704
Highly Voted 4 months ago
Selected Answer: BCE
Pagina 186 When a certificate fails for any of the reasons above, you can configure any of the following actions: • Keep untrusted & Allow: FortiGate allows the website and lets the browser decide the action to take. FortiGate takes the certificate as untrusted. • Block: FortiGate blocks the content of the site. • Trust & Allow: FortiGate allows the website and takes the certificate as trusted.
upvoted 9 times
...
andres8h
Highly Voted 4 months, 1 week ago
Selected Answer: ABE
ABE is correct fortigate 7.4 Administrator pag 186
upvoted 7 times
fa7474b
2 months, 1 week ago
I believe A is incorrect. Page 186 of the study guide does not contain the word "warning" anywhere on it. I take "Warning" in this context to mean that Fortigate would supply a warning. That is not what happens. If you set it to "Keep untrusted and allow" then the BROWSER will generate the warning, NOT Fortigate.
upvoted 4 times
...
...
hecjoseroag
Most Recent 4 weeks, 1 day ago
Selected Answer: BCE
BCE Keep Untrusted & Allow: Allow the server certificate and keep it untrusted.l Block: Block the certificate.l Trust & Allow: Allow the server certificate and re-sign it as trusted (page 1966 FortiOS Administrator Guide)
upvoted 2 times
...
sxcap
1 month ago
Selected Answer: BCE
Options available: Trust and Allow (fortigate marks the certificate as trusted) Keep untrusted and allow / allow (Fortigate allow the traffic and let the browser decide) Block (Fortigate blocks the connection)
upvoted 2 times
...
JRKhan
1 month, 3 weeks ago
Selected Answer: BCE
With invalid certificates the options are Allow, Block or Custom. In custom, you can either select: Trust & Allow, Keep Untrusted and Allow, Block. So BCE is correct.
upvoted 3 times
...
s4mu3l007
2 months, 1 week ago
BCE are correct
upvoted 2 times
...
066c9f3
2 months, 1 week ago
Selected Answer: BCE
I'd go with BCE because on FortiGate it says "Keep untrusted & Allow", "Block", "Trust & Allow". With "Keep untrusted & Allow", Fortigate allows it and does NOT display a warning but let's the browser decide. I'd associate the Fortigate setting "Keep untrusted & allow" with "Allow" from the question (Option C). Anything else doesn't make sense. Since there's no warning displayed in any allow situation, A doesn't make sense and since Block & Warning doesn't exist, it has to be B for this. The other two (Trust & Allow, Block) are the exact same words as written in the question, so it can only be B, C, E.
upvoted 4 times
...
marcovinicius4
2 months, 1 week ago
Selected Answer: BCE
In "SSL/SSH Inspection" > Create New I can set in "Common Options" Invalid SSL certificates: Allow | Bloc | Custom - Expired certificates: Keep Untrusted & Allow | Block | Trust & Allow - Revoke certificates: Keep Untrusted & Allow | Block | Trust & Allow - Validation time-out certificates: Keep Untrusted & Allow | Block | Trust & Allow - Validation failed certificates: Keep Untrusted & Allow | Block | Trust & Allow
upvoted 4 times
...
DBFront
2 months, 3 weeks ago
Selected Answer: ABE
ABE
upvoted 1 times
...
6f7d62a
3 months ago
Selected Answer: BCE
In the administration guide you can confirm that there are only the options to allow or block, after enabling deep inspection, the options to trust or not trust the certificate are added.
upvoted 5 times
...
0d6e481
3 months ago
Selected Answer: BCE
There's no Warning in SSL inspection. Warning exists for Web Filter
upvoted 4 times
...
miguelmagr
3 months, 1 week ago
Selected Answer: BCE
Allow Trust & Allow Block
upvoted 5 times
...
dumpz
3 months, 1 week ago
Answer it's BCE on the fortinet guide there is written allow, trust & allow and block
upvoted 4 times
...
Billyon
4 months ago
Selected Answer: ABE
The illustration on Page 186
upvoted 3 times
...
Vdiaz
4 months ago
In Untrusted and allow option Fortigate show a warning, that's why A is correct
upvoted 1 times
...
bob511
4 months, 1 week ago
BCE is correct fortigate 7.4 Administrator page 186 " a certificate fails for any of the reasons above, you can configure any of the following actions: • Keep untrusted & Allow: FortiGate allows the website and lets the browser decide the action to take. FortiGate takes the certificate as untrusted. • Block: FortiGate blocks the content of the site. • Trust & Allow: FortiGate allows the website and takes the certificate as trusted."
upvoted 2 times
bob511
4 months, 1 week ago
NM its ABE as allow is not an option and the keep untrusted will show a warning so A is correct
upvoted 2 times
...
...
Qwerty379
4 months, 1 week ago
Selected Answer: BCE
It should be BCE
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago