Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Full SSL SSH Inspection And Endpoint Trust Practice Test

 

This Fortinet NSE4_FGT_AD-7.6 practice test focuses on full ssl ssh inspection and endpoint trust through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.

Question 1

While troubleshooting at Humongous Insurance, the SOC analyst needs to inspect malware and application payload inside outbound HTTPS sessions. What is the best next step? No unrelated security controls should be changed.

  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior

Correct answer: B

Explanation

  1. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  2. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This directly satisfies the stated requirement.
  3. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  4. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  5. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.

Learning point: For this FortiOS 7.6 scenario, apply a full SSL inspection profile to the matching policy along with the required security profiles. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads.

Question 2

Coho Winery is standardizing its FortiGate 7.6 operations. Which approach should it use to understand why certificate inspection cannot detect a malicious file carried inside HTTPS? The administrator wants a configuration that is easy to audit later.

  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate

Correct answer: B

Explanation

  1. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  2. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This directly satisfies the stated requirement.
  3. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  4. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  5. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.

Learning point: For this FortiOS 7.6 scenario, use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content. Certificate inspection evaluates handshake and certificate information without exposing the application payload.

Question 3

A production ticket for Relecloud states that administrators must prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection. Which choice is correct? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: B

Explanation

  1. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  2. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This directly satisfies the stated requirement.
  3. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  4. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.

Learning point: For this FortiOS 7.6 scenario, deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates.

Question 4

The security team at Woodgrove Bank wants to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA. Which FortiGate configuration or action most directly meets that goal? The team wants the smallest change that directly addresses the requirement.

  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application

Correct answer: A

Explanation

  1. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This directly satisfies the stated requirement.
  2. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  3. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  4. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  5. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.

Learning point: For this FortiOS 7.6 scenario, install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates.

Question 5

An incident at Alpine Ski House requires the SOC analyst to troubleshoot browser warnings that started immediately after enabling full inspection. What should be done first? The choice should follow normal FortiOS administration practice.

  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: A

Explanation

  1. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This directly satisfies the stated requirement.
  2. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  3. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  4. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.

Learning point: For this FortiOS 7.6 scenario, verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain. An untrusted inspection CA is a common cause of browser warnings during TLS interception.

Question 6

For a FortiGate 7.6 deployment at Datum Corporation, which option correctly addresses the need to handle an application that uses certificate pinning and fails only when deep inspection is enabled? The solution must preserve the existing production design where possible.

  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content

Correct answer: C

Explanation

  1. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  2. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  3. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This directly satisfies the stated requirement.
  4. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  5. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.

Learning point: For this FortiOS 7.6 scenario, evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review.

Question 7

Southridge Video has validated routing and basic reachability. The remaining requirement is to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions. Which action should the team take? The change is being made during a controlled production window.

  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: D

Explanation

  1. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  2. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  3. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  4. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This directly satisfies the stated requirement.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.

Learning point: For this FortiOS 7.6 scenario, recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions.

Question 8

At Fabrikam Manufacturing, a network administrator is handling a FortiGate 7.6 change. The requirement is to inspect supported encrypted SSH traffic under a policy. What should the administrator do? The team will validate the result immediately after the change.

  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content

Correct answer: C

Explanation

  1. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  2. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  3. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This directly satisfies the stated requirement.
  4. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  5. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.

Learning point: For this FortiOS 7.6 scenario, apply an SSL/SSH inspection profile that enables the required SSH inspection behavior. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH.

Question 9

During a maintenance window at Wingtip Energy, the team must inspect malware and application payload inside outbound HTTPS sessions. Which action is the most appropriate? No unrelated security controls should be changed.

  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: E

Explanation

  1. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  2. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  3. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  4. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, apply a full SSL inspection profile to the matching policy along with the required security profiles. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads.

Question 10

A change review at Lucerne Publishing identifies one requirement: understand why certificate inspection cannot detect a malicious file carried inside HTTPS. Which FortiGate action best satisfies it? The administrator wants a configuration that is easy to audit later.

  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain

Correct answer: C

Explanation

  1. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  2. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  3. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This directly satisfies the stated requirement.
  4. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  5. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.

Learning point: For this FortiOS 7.6 scenario, use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content. Certificate inspection evaluates handshake and certificate information without exposing the application payload.

Question 11

While troubleshooting at School of Fine Art, the SOC analyst needs to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection. What is the best next step? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate

Correct answer: E

Explanation

  1. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  2. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  3. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  4. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  5. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates.

Question 12

Apex Retail is standardizing its FortiGate 7.6 operations. Which approach should it use to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA? The team wants the smallest change that directly addresses the requirement.

  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: B

Explanation

  1. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  2. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This directly satisfies the stated requirement.
  3. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  4. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.

Learning point: For this FortiOS 7.6 scenario, install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates.

Question 13

A production ticket for Proseware Media states that administrators must troubleshoot browser warnings that started immediately after enabling full inspection. Which choice is correct? The choice should follow normal FortiOS administration practice.

  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain

Correct answer: E

Explanation

  1. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  2. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  3. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  4. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  5. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain. An untrusted inspection CA is a common cause of browser warnings during TLS interception.

Question 14

The security team at City Power & Light wants to handle an application that uses certificate pinning and fails only when deep inspection is enabled. Which FortiGate configuration or action most directly meets that goal? The solution must preserve the existing production design where possible.

  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: D

Explanation

  1. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  2. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  3. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  4. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This directly satisfies the stated requirement.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.

Learning point: For this FortiOS 7.6 scenario, evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review.

Question 15

An incident at Margie Travel requires the SOC analyst to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions. What should be done first? The change is being made during a controlled production window.

  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content

Correct answer: B

Explanation

  1. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  2. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This directly satisfies the stated requirement.
  3. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  4. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  5. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.

Learning point: For this FortiOS 7.6 scenario, recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions.

Question 16

For a FortiGate 7.6 deployment at Bellows College, which option correctly addresses the need to inspect supported encrypted SSH traffic under a policy? The team will validate the result immediately after the change.

  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain

Correct answer: B

Explanation

  1. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  2. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This directly satisfies the stated requirement.
  3. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  4. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  5. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.

Learning point: For this FortiOS 7.6 scenario, apply an SSL/SSH inspection profile that enables the required SSH inspection behavior. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH.

Question 17

Adventure Works has validated routing and basic reachability. The remaining requirement is to inspect malware and application payload inside outbound HTTPS sessions. Which action should the team take? No unrelated security controls should be changed.

  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application

Correct answer: D

Explanation

  1. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  2. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  3. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  4. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This directly satisfies the stated requirement.
  5. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.

Learning point: For this FortiOS 7.6 scenario, apply a full SSL inspection profile to the matching policy along with the required security profiles. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads.

Question 18

At Fourth Coffee, a network administrator is handling a FortiGate 7.6 change. The requirement is to understand why certificate inspection cannot detect a malicious file carried inside HTTPS. What should the administrator do? The administrator wants a configuration that is easy to audit later.

  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles

Correct answer: B

Explanation

  1. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  2. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This directly satisfies the stated requirement.
  3. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  4. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.
  5. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand why certificate inspection cannot detect a malicious file carried inside HTTPS.

Learning point: For this FortiOS 7.6 scenario, use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content. Certificate inspection evaluates handshake and certificate information without exposing the application payload.

Question 19

During a maintenance window at Consolidated Messenger, the team must prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection. Which action is the most appropriate? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions

Correct answer: A

Explanation

  1. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This directly satisfies the stated requirement.
  2. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  3. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  4. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.
  5. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent browser warnings caused by FortiGate re-signing outbound certificates during full inspection.

Learning point: For this FortiOS 7.6 scenario, deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates.

Question 20

A change review at VanArsdel identifies one requirement: use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA. Which FortiGate action best satisfies it? The team wants the smallest change that directly addresses the requirement.

  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application

Correct answer: C

Explanation

  1. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  2. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  3. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This directly satisfies the stated requirement.
  4. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.
  5. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to use the enterprise PKI for outbound deep inspection instead of the default FortiGate CA.

Learning point: For this FortiOS 7.6 scenario, install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates.

Question 21

While troubleshooting at Northwind Health, the SOC analyst needs to troubleshoot browser warnings that started immediately after enabling full inspection. What is the best next step? The choice should follow normal FortiOS administration practice.

  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application

Correct answer: D

Explanation

  1. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  2. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  3. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.
  4. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This directly satisfies the stated requirement.
  5. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot browser warnings that started immediately after enabling full inspection.

Learning point: For this FortiOS 7.6 scenario, verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain. An untrusted inspection CA is a common cause of browser warnings during TLS interception.

Question 22

Blue Yonder Airlines is standardizing its FortiGate 7.6 operations. Which approach should it use to handle an application that uses certificate pinning and fails only when deep inspection is enabled? The solution must preserve the existing production design where possible.

  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application

Correct answer: E

Explanation

  1. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  2. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  3. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  4. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle an application that uses certificate pinning and fails only when deep inspection is enabled.
  5. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review.

Question 23

A production ticket for Trey Research states that administrators must explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions. Which choice is correct? The change is being made during a controlled production window.

  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Use full SSL inspection when payload inspection is required because certificate inspection does not decrypt the encrypted content
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior

Correct answer: A

Explanation

  1. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This directly satisfies the stated requirement.
  2. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  3. Certificate inspection evaluates handshake and certificate information without exposing the application payload. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  4. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.
  5. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain how FortiGate can inspect encrypted traffic without possessing the origin server private key for outbound sessions.

Learning point: For this FortiOS 7.6 scenario, recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions.

Question 24

The security team at Nod Publishers wants to inspect supported encrypted SSH traffic under a policy. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.

  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Install an appropriate CA certificate and private key on FortiGate and ensure the enterprise endpoints trust that CA
  • Recognize that FortiGate proxies the connection into separate client-to-FortiGate and FortiGate-to-server TLS sessions

Correct answer: B

Explanation

  1. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  2. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This directly satisfies the stated requirement.
  3. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  4. A CA-capable certificate trusted by endpoints can be used by FortiGate to re-sign inspected server certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.
  5. Full outbound inspection works by acting as an intermediary and creating separate TLS sessions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect supported encrypted SSH traffic under a policy.

Learning point: For this FortiOS 7.6 scenario, apply an SSL/SSH inspection profile that enables the required SSH inspection behavior. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH.

Question 25

An incident at Contoso Finance requires the SOC analyst to inspect malware and application payload inside outbound HTTPS sessions. What should be done first? No unrelated security controls should be changed.

  • Deploy the CA certificate used by FortiGate for re-signing as a trusted CA on managed endpoints or use a suitable enterprise-issued CA certificate
  • Apply an SSL/SSH inspection profile that enables the required SSH inspection behavior
  • Evaluate a narrowly scoped SSL inspection exemption or alternative security treatment for that application
  • Apply a full SSL inspection profile to the matching policy along with the required security profiles
  • Verify endpoint trust of the FortiGate inspection CA and inspect the replacement certificate chain

Correct answer: D

Explanation

  1. Clients must trust the issuing CA that FortiGate uses for dynamically generated replacement certificates. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  2. SSL/SSH inspection profiles control FortiGate inspection of supported encrypted protocols including SSH. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  3. Certificate pinning can reject dynamically re-signed certificates, so selected traffic may require an exception after risk review. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.
  4. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads. This directly satisfies the stated requirement.
  5. An untrusted inspection CA is a common cause of browser warnings during TLS interception. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect malware and application payload inside outbound HTTPS sessions.

Learning point: For this FortiOS 7.6 scenario, apply a full SSL inspection profile to the matching policy along with the required security profiles. Full inspection decrypts and re-encrypts TLS so security engines can inspect encrypted payloads.

Popular posts

img