Fortinet Enterprise Firewall 7.6 FCSS_EFW_AD-7.6 SSL And SSH Inspection Certificate Strategy Practice Test
This practice test focuses on ssl and ssh inspection certificate strategy through original applied scenarios aligned to the final published Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator 7.6 blueprint. It is intended for study and does not reproduce live exam content. For broader exam preparation, review the Fortinet FCSS_EFW_AD-7.6 Exam Dumps page.
Question 1
At Blue Yonder Airlines, the security infrastructure engineer must inspect HTTPS payloads for malware and application signatures. Which action best addresses the requirement? The team needs an auditable result. Only one site is affected; peer sites are healthy.
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Use certificate-inspection behavior rather than full content decryption
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
Correct answer: A
Explanation
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This directly addresses the stated requirement.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate. Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain.
Question 2
During an enterprise firewall change at Trey Research, the team needs to check certificate properties without decrypting application payloads. What should it do? Use normal enterprise Fortinet administration practice. The change must be validated on a pilot device before broader rollout.
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use certificate-inspection behavior rather than full content decryption
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: D
Explanation
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This directly addresses the stated requirement.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use certificate-inspection behavior rather than full content decryption. Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload.
Question 3
A production review at Apex Retail identifies this requirement: exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. Existing production IP addressing must remain unchanged.
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
Correct answer: A
Explanation
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This directly addresses the stated requirement.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the narrowest supported SSL-inspection exemption for the required destination or category. Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement.
Question 4
While troubleshooting at Proseware Media, the network security architect needs to eliminate browser trust warnings caused by the inspection CA not being trusted. What is the best next step? No unrelated control should be weakened. The resulting configuration must remain centrally auditable.
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use certificate-inspection behavior rather than full content decryption
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
Correct answer: C
Explanation
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Clients must trust the CA that signs substituted certificates during deep inspection. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store. Clients must trust the CA that signs substituted certificates during deep inspection.
Question 5
City Power & Light is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to troubleshoot an application that fails only when deep inspection is enabled? The team will validate the result immediately after the change. A known-good rollback point is available before the change.
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
Correct answer: C
Explanation
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This directly addresses the stated requirement.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally. Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly.
Question 6
A change ticket for VanArsdel states that administrators must inspect administrative SSH sessions according to policy. Which choice is correct? The change is taking place in a controlled maintenance window. The design must preserve the current segmentation boundaries.
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
Correct answer: D
Explanation
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This directly addresses the stated requirement.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior. SSH inspection must be explicitly configured and matched to the policy handling the session.
Question 7
The security team at Woodgrove Bank wants to inspect HTTPS payloads for malware and application signatures. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The team is not allowed to disable the security feature globally.
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use certificate-inspection behavior rather than full content decryption
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: D
Explanation
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This directly addresses the stated requirement.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate. Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain.
Question 8
An incident at Alpine Ski House requires the NOC engineer to check certificate properties without decrypting application payloads. What should be done first? The answer must address the stated cause rather than a different feature. The symptom appeared immediately after a planned configuration change.
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use certificate-inspection behavior rather than full content decryption
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: D
Explanation
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This directly addresses the stated requirement.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use certificate-inspection behavior rather than full content decryption. Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload.
Question 9
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Datum Corporation, which option correctly addresses the need to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere? Preserve the existing design unless the requirement says otherwise. Logs from the affected traffic are available for verification.
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use certificate-inspection behavior rather than full content decryption
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
Correct answer: C
Explanation
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the narrowest supported SSL-inspection exemption for the required destination or category. Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement.
Question 10
Contoso Finance has verified basic IP reachability. The remaining requirement is to eliminate browser trust warnings caused by the inspection CA not being trusted. Which action should the team take? Prefer a change that is reversible and easy to verify. The equivalent configuration works correctly at a separate site.
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use certificate-inspection behavior rather than full content decryption
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
Correct answer: C
Explanation
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Clients must trust the CA that signs substituted certificates during deep inspection. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store. Clients must trust the CA that signs substituted certificates during deep inspection.
Question 11
At Litware Logistics, the Fortinet administrator must troubleshoot an application that fails only when deep inspection is enabled. Which action best addresses the requirement? The team needs an auditable result. The change must be reversible within the same maintenance window.
- Use certificate-inspection behavior rather than full content decryption
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
Correct answer: E
Explanation
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally. Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly.
Question 12
During an enterprise firewall change at Wide World Importers, the team needs to inspect administrative SSH sessions according to policy. What should it do? Use normal enterprise Fortinet administration practice. The device is already synchronized with its central-management database.
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Use certificate-inspection behavior rather than full content decryption
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
Correct answer: C
Explanation
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior. SSH inspection must be explicitly configured and matched to the policy handling the session.
Question 13
A production review at Relecloud identifies this requirement: inspect HTTPS payloads for malware and application signatures. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. The current routing table contains the expected connected networks.
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Use certificate-inspection behavior rather than full content decryption
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
Correct answer: B
Explanation
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate. Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain.
Question 14
While troubleshooting at Adventure Works, the NOC engineer needs to check certificate properties without decrypting application payloads. What is the best next step? No unrelated control should be weakened. Basic IP reachability to the remote endpoint has already been verified.
- Use certificate-inspection behavior rather than full content decryption
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
Correct answer: A
Explanation
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This directly addresses the stated requirement.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use certificate-inspection behavior rather than full content decryption. Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload.
Question 15
Fourth Coffee is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere? The team will validate the result immediately after the change. Hardware replacement is outside the approved change scope.
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use certificate-inspection behavior rather than full content decryption
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: E
Explanation
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the narrowest supported SSL-inspection exemption for the required destination or category. Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement.
Question 16
A change ticket for Coho Winery states that administrators must eliminate browser trust warnings caused by the inspection CA not being trusted. Which choice is correct? The change is taking place in a controlled maintenance window. The requirement applies only to one policy, peer, or managed device group.
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: C
Explanation
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Clients must trust the CA that signs substituted certificates during deep inspection. This directly addresses the stated requirement.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store. Clients must trust the CA that signs substituted certificates during deep inspection.
Question 17
The security team at Fabrikam Manufacturing wants to troubleshoot an application that fails only when deep inspection is enabled. Which configuration or operational action most directly satisfies that goal? Choose the smallest targeted change. The team must avoid broadening administrative trust or permissions.
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use certificate-inspection behavior rather than full content decryption
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: A
Explanation
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally. Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly.
Question 18
An incident at Wingtip Energy requires the network operations engineer to inspect administrative SSH sessions according to policy. What should be done first? The answer must address the stated cause rather than a different feature. The design must preserve existing centralized logging and telemetry.
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Use certificate-inspection behavior rather than full content decryption
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
Correct answer: B
Explanation
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This directly addresses the stated requirement.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior. SSH inspection must be explicitly configured and matched to the policy handling the session.
Question 19
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Lucerne Publishing, which option correctly addresses the need to inspect HTTPS payloads for malware and application signatures? Preserve the existing design unless the requirement says otherwise. Production subnets cannot be renumbered as part of this change.
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
Correct answer: A
Explanation
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This directly addresses the stated requirement.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate. Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain.
Question 20
Bellows College has verified basic IP reachability. The remaining requirement is to check certificate properties without decrypting application payloads. Which action should the team take? Prefer a change that is reversible and easy to verify. A maintenance window is open, but service interruption must be minimized.
- Use certificate-inspection behavior rather than full content decryption
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Create the narrowest supported SSL-inspection exemption for the required destination or category
Correct answer: A
Explanation
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This directly addresses the stated requirement.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to check certificate properties without decrypting application payloads.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use certificate-inspection behavior rather than full content decryption. Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload.
Question 21
At Tailspin Toys, the enterprise firewall engineer must exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere. Which action best addresses the requirement? The team needs an auditable result. The team must preserve existing certificate-trust relationships unless the requirement explicitly changes them.
- Use certificate-inspection behavior rather than full content decryption
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
Correct answer: B
Explanation
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This directly addresses the stated requirement.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to exclude a legally sensitive destination from deep decryption while keeping inspection elsewhere.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create the narrowest supported SSL-inspection exemption for the required destination or category. Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement.
Question 22
During an enterprise firewall change at Humongous Insurance, the team needs to eliminate browser trust warnings caused by the inspection CA not being trusted. What should it do? Use normal enterprise Fortinet administration practice. The change will be reviewed later using the configuration and event audit trail.
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
Correct answer: E
Explanation
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to eliminate browser trust warnings caused by the inspection CA not being trusted.
- Clients must trust the CA that signs substituted certificates during deep inspection. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store. Clients must trust the CA that signs substituted certificates during deep inspection.
Question 23
A production review at Margie Travel identifies this requirement: troubleshoot an application that fails only when deep inspection is enabled. Which Fortinet action is most appropriate? Assume the platform versions are compatible with the feature. The chosen approach must continue to work as additional branch sites are added.
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Use certificate-inspection behavior rather than full content decryption
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
Correct answer: D
Explanation
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This directly addresses the stated requirement.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to troubleshoot an application that fails only when deep inspection is enabled.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally. Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly.
Question 24
While troubleshooting at Northwind Health, the network operations engineer needs to inspect administrative SSH sessions according to policy. What is the best next step? No unrelated control should be weakened. A second engineer will verify the result using independent operational evidence.
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Confirm certificate validation, TLS-version compatibility, exemption requirements, and inspection logs before disabling the profile globally
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
Correct answer: E
Explanation
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Deep inspection can expose certificate pinning or TLS compatibility issues that should be diagnosed narrowly. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect administrative SSH sessions according to policy.
- SSH inspection must be explicitly configured and matched to the policy handling the session. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior. SSH inspection must be explicitly configured and matched to the policy handling the session.
Question 25
Blue Yonder Airlines is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to inspect HTTPS payloads for malware and application signatures? The team will validate the result immediately after the change. The team requires a deterministic rollback path if validation fails.
- Use an SSH inspection mode/profile supported for the scenario and validate the resulting inspection and logging behavior
- Use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate
- Deploy the FortiGate inspection CA certificate to managed endpoints through the enterprise trust store
- Create the narrowest supported SSL-inspection exemption for the required destination or category
- Use certificate-inspection behavior rather than full content decryption
Correct answer: B
Explanation
- SSH inspection must be explicitly configured and matched to the policy handling the session. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain. This directly addresses the stated requirement.
- Clients must trust the CA that signs substituted certificates during deep inspection. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Targeted exemptions preserve broad inspection coverage while honoring the specific no-decrypt requirement. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
- Certificate inspection can validate and classify TLS sessions without proxying the full encrypted payload. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to inspect HTTPS payloads for malware and application signatures.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a full or deep SSL inspection profile and ensure endpoints trust the issuing CA used by FortiGate. Payload inspection of HTTPS requires decryption and endpoint trust of the inspection certificate chain.