exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 13 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 13
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate.
Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choose three.)

  • A. Allow & Warning
  • B. Trust & Allow
  • C. Allow
  • D. Block & Warning
  • E. Block
Show Suggested Answer Hide Answer
Suggested Answer: BCE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IBB90704
Highly Voted 5 months, 3 weeks ago
Selected Answer: BCE
Pagina 186 When a certificate fails for any of the reasons above, you can configure any of the following actions: • Keep untrusted & Allow: FortiGate allows the website and lets the browser decide the action to take. FortiGate takes the certificate as untrusted. • Block: FortiGate blocks the content of the site. • Trust & Allow: FortiGate allows the website and takes the certificate as trusted.
upvoted 12 times
...
andres8h
Highly Voted 6 months ago
Selected Answer: ABE
ABE is correct fortigate 7.4 Administrator pag 186
upvoted 7 times
fa7474b
4 months ago
I believe A is incorrect. Page 186 of the study guide does not contain the word "warning" anywhere on it. I take "Warning" in this context to mean that Fortigate would supply a warning. That is not what happens. If you set it to "Keep untrusted and allow" then the BROWSER will generate the warning, NOT Fortigate.
upvoted 4 times
...
...
Nicae
Most Recent 1 week, 4 days ago
Selected Answer: ABE
ABE according to page 186 of the study guide, it states Keep Untrusted and Allow Block Trust and Allow for A: Allow and Warning would be the same as keep untrusted and Allow because the warning shows that it is untrusted but you are able to continue. with B and E stating to either block the content or trust the website and gain access. I Page 186 of the study guide never stated any other actions from C and D from what I can see in the options.
upvoted 1 times
...
Ajit9929
4 weeks, 1 day ago
Selected Answer: ADE
Only 3 valid actions - allow & warning, block and warning and block
upvoted 2 times
...
harizmr
1 month ago
Selected Answer: ABE
ABE is correct fortigate 7.4 Administrator pag 186
upvoted 1 times
...
hecjoseroag
2 months, 2 weeks ago
Selected Answer: BCE
BCE Keep Untrusted & Allow: Allow the server certificate and keep it untrusted.l Block: Block the certificate.l Trust & Allow: Allow the server certificate and re-sign it as trusted (page 1966 FortiOS Administrator Guide)
upvoted 2 times
...
sxcap
2 months, 3 weeks ago
Selected Answer: BCE
Options available: Trust and Allow (fortigate marks the certificate as trusted) Keep untrusted and allow / allow (Fortigate allow the traffic and let the browser decide) Block (Fortigate blocks the connection)
upvoted 2 times
...
JRKhan
3 months, 2 weeks ago
Selected Answer: BCE
With invalid certificates the options are Allow, Block or Custom. In custom, you can either select: Trust & Allow, Keep Untrusted and Allow, Block. So BCE is correct.
upvoted 3 times
...
s4mu3l007
3 months, 4 weeks ago
BCE are correct
upvoted 2 times
...
066c9f3
4 months ago
Selected Answer: BCE
I'd go with BCE because on FortiGate it says "Keep untrusted & Allow", "Block", "Trust & Allow". With "Keep untrusted & Allow", Fortigate allows it and does NOT display a warning but let's the browser decide. I'd associate the Fortigate setting "Keep untrusted & allow" with "Allow" from the question (Option C). Anything else doesn't make sense. Since there's no warning displayed in any allow situation, A doesn't make sense and since Block & Warning doesn't exist, it has to be B for this. The other two (Trust & Allow, Block) are the exact same words as written in the question, so it can only be B, C, E.
upvoted 4 times
...
marcovinicius4
4 months ago
Selected Answer: BCE
In "SSL/SSH Inspection" > Create New I can set in "Common Options" Invalid SSL certificates: Allow | Bloc | Custom - Expired certificates: Keep Untrusted & Allow | Block | Trust & Allow - Revoke certificates: Keep Untrusted & Allow | Block | Trust & Allow - Validation time-out certificates: Keep Untrusted & Allow | Block | Trust & Allow - Validation failed certificates: Keep Untrusted & Allow | Block | Trust & Allow
upvoted 4 times
...
DBFront
4 months, 1 week ago
Selected Answer: ABE
ABE
upvoted 1 times
...
6f7d62a
4 months, 2 weeks ago
Selected Answer: BCE
In the administration guide you can confirm that there are only the options to allow or block, after enabling deep inspection, the options to trust or not trust the certificate are added.
upvoted 5 times
...
0d6e481
4 months, 3 weeks ago
Selected Answer: BCE
There's no Warning in SSL inspection. Warning exists for Web Filter
upvoted 4 times
...
miguelmagr
5 months ago
Selected Answer: BCE
Allow Trust & Allow Block
upvoted 5 times
...
dumpz
5 months ago
Answer it's BCE on the fortinet guide there is written allow, trust & allow and block
upvoted 4 times
...
Billyon
5 months, 3 weeks ago
Selected Answer: ABE
The illustration on Page 186
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago