exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 11 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 11
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)

  • A. The client FortiGate requires a manually added route to remote subnets.
  • B. The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
  • C. The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
  • D. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
raydel92
Highly Voted 1 year, 3 months ago
Selected Answer: CD
C. The server FortiGate requires a CA certificate to verify the client FortiGate certificate. D. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN. FortiGate Infrastructure 7.2 Study Guide (p.200): "The FortiGate can be configured as an SSL VPN client, using an SSL-VPN Tunnel interface type" "The FortiGate devices must have the proper CA certificate installed to verify the certificate chain to the root CA that signed the certificate." Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
upvoted 6 times
netwkguy99
1 year, 3 months ago
What if they are using Web Mode SSL VPN?
upvoted 1 times
paulosrsf
11 months, 2 weeks ago
The question is not considering SSL VPN for client workstations. It is asking about a Fortigate firewall acting as a SSL VPN client. So the aproach is a little bit different from a client computer and Web mode does not apply in this situation.
upvoted 1 times
...
...
...
flamengo
Most Recent 5 months, 2 weeks ago
Does anyone know if new questions were added in version FGT-7.4?
upvoted 1 times
...
BIGFATNUTS
6 months ago
CD is correct. C: Server makes PKI user with CA cert. Server verifies and client authenticates with same CA cert. D: The client configures an SSLVPN Tunnel interface. B is incorrect. There are no client certificates used, only CA certs.
upvoted 1 times
...
Mqbx
8 months, 3 weeks ago
Selected Answer: CD
C y D en Security para tunnel mode - Fortigate as client: Requires proper CA certificate on SSL VPN Server Fortigate. Use SSL VPN Tunnel interface type.
upvoted 1 times
...
GopiChandMurari
8 months, 3 weeks ago
To establish an SSL VPN connection between two FortiGate devices, the following two settings are required: B. The client FortiGate requires a client certificate signed by the CA on the server FortiGate. This ensures mutual authentication between the two devices, where the server verifies the client's certificate during the SSL handshake. C. The server FortiGate requires a CA certificate to verify the client FortiGate certificate. This is necessary for the server to authenticate the client's certificate. So, the correct options are B and C.
upvoted 2 times
...
Slash_JM
1 year, 4 months ago
Selected Answer: CD
FortiGate Infrastructure 7.2 Study Guide p.200
upvoted 2 times
...
darkstar15
1 year, 5 months ago
C y D en Security para tunnel mode - Fortigate as client: Requires proper CA certificate on SSL VPN Server Fortigate. Use SSL VPN Tunnel interface type.
upvoted 1 times
...
umairmasood
1 year, 6 months ago
C and D
upvoted 1 times
...
Danny_B
1 year, 7 months ago
Selected Answer: CD
7.2 SEC 200
upvoted 2 times
Danny_B
1 year, 7 months ago
correction 7.2 INF 200
upvoted 4 times
...
...
PaulGo
1 year, 8 months ago
Selected Answer: CD
Security pag 582 This configuration requires proper CA certificate installatin as the SSL VPN cliente FortiGate/user uses PSK and a PKI client certificate to authenticate. The FG devices must have the proper CA certificaate installed to verity the certificate chain to the root CA that signed the certificate. link: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/508779/fortigate-as-ssl-vpn-client The SSL VPN server has a custom server certificate defined, and the SSL VPN client user uses PSK and a PKI client certificate to authenticate. The FortiGates must have the proper CA certificate installed to verify the certificate chain to the root CA that signed the certificate.
upvoted 2 times
...
santi1509
1 year, 10 months ago
Selected Answer: BC
El cliente debe instalar en su maquina local el software de autenticación el cual es el encargado de establecer la firma HA, este mismo es enviado al FortiGate el cual almacena el certificado HA. Cada vez que se vaya a hacer una conexión o petición el FortiGate compara los dos certificados, y si concuerdan, deja pasar la petición
upvoted 2 times
D1360_1304
1 year, 4 months ago
He always puts the answers wrong
upvoted 4 times
...
IckoPCNSE
1 year, 10 months ago
So you mean CD are the correct answers right ?
upvoted 1 times
Malamba
1 year, 9 months ago
Yeah CD are correct
upvoted 1 times
...
...
spiku
1 year, 4 months ago
No matter when you read Santi, unfortunately he's always wrong. Seems done on purpose.
upvoted 3 times
...
...
BoostBoris
1 year, 10 months ago
Selected Answer: CD
C: This configuration requires proper CA certificate installation as the SSL VPN client FortiGate/user uses PSK and a PKI client certificate to authenticate. The FortiGate devices must have the proper CA certificate installed to verify the certificate chain to the root CA that signed the certificate. D: The FortiGate can be configured as an SSL VPN client, using an SSL-VPN Tunnel interface type.
upvoted 1 times
...
leadac
1 year, 11 months ago
Selected Answer: CD
https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/508779/fortigate-as-ssl-vpn-client The FortiGate can be configured as an SSL VPN client, using an SSL-VPN Tunnel interface type. The FortiGates must have a proper CA certificate installed to verify the certificate chain to the root CA that signed the certificate.
upvoted 3 times
...
chiheb
1 year, 11 months ago
Selected Answer: CD
C and D are the right answers.
upvoted 1 times
...
Spago
1 year, 11 months ago
Selected Answer: CD
C. The server FortiGate requires a CA certificate to verify the client FortiGate certificate. D. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN. To establish an SSL VPN connection between two FortiGate devices, the following two settings are required: The server FortiGate requires a CA certificate to verify the client FortiGate certificate: The server FortiGate will use a CA (Certificate Authority) certificate to verify the client FortiGate certificate, ensuring that the client device is trusted and allowed to establish an SSL VPN connection. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN: The client FortiGate must have an SSL VPN tunnel interface type configured in order to establish an SSL VPN connection. This interface type will be used to connect to the server FortiGate over the SSL VPN.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago