exam questions

Exam NSE8_811 All Questions

View all questions & answers for the NSE8_811 exam

Exam NSE8_811 topic 1 question 54 discussion

Actual exam question from Fortinet's NSE8_811
Question #: 54
Topic #: 1
[All NSE8_811 Questions]

You configured a firewall policy with only a Web filter profile for accessing the Internet. Access to websites belonging to the "Information Technology" category are blocked and to the "Business" category are allowed. SSL deep inspection is not enabled on this policy.
A user wants to access the website https://www.it-acme.com which presents a certificate with CN=www.acme.com. The it-acme.com domain is categorized as
"Information Technology" and the acme.com domain is categorized as "Business".
Which statement regarding this scenario is correct?

  • A. The FortiGate is able to read the URL within HTTPS sessions when using SSL certificate inspection so the website will be blocked by the "Information Technology".
  • B. The website will be blocked by category "Information Technology" as the SNI takes precedence over the certificate name.
  • C. The website will be allowed by category "Business" as the certificate name takes precedence over the URL.
  • D. Only with SSL deep inspection enabled will the FortiGate be able to categorized this website.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sb_2021
3 years, 3 months ago
Selected Answer: B
https://community.fortinet.com/t5/FortiGate/HTTPS-Webfiltering-without-deep-scan-enabled-details/ta-p/197546?externalID=FD34661
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago