What attribute or extension is used to identify the owner of a certificate?
Respuesta
a. The subject name in the certificate
b. The unique serial number in the certificate
Pregunta 3
Pregunta
How does FortiGate check to see if a certificate has been revoked?
Respuesta
a. It checks the CRL that resides on FortiGate.
b. It retrieves the CRL from a directory server.
Pregunta 4
Pregunta
Which one of the following is a certificate extension and value that is required in the FortiGate CA certificate in order to enable full SSL inspection?
Respuesta
a. CRL DP=ca_arl.arl
b. cA=True
Pregunta 5
Pregunta
For full SSL inspection, which configuration requires FortiGate to act as a CA?
Respuesta
a. Multiple clients connecting to multiple servers
b. Protecting the SSL server
Pregunta 6
Pregunta
Deleting a CSR that is a pending state does not impact your ability to install the certificate.
Respuesta
a. True
b. False
Pregunta 7
Pregunta
What is one reason why a CA would trust and accept a CSR from a FortiGate?
Respuesta
a. The CSR is signed by the FortiGate’s private key.
b. The CA inherently trusts all FortiGates.
Pregunta 8
Pregunta
To be compliant with the Internet Engineering Task Force (IETF) RFC 5280, the CA certificate requires these two extensions to issue certificates:
Respuesta
cA=True
keyUsage=keyCertSign
cA=True
RFC=5280
Pregunta 9
Pregunta
Untrusted SSL Certificates options: (select 3)
Respuesta
Allow
Block
Ignore
Log only
Default
Quarantine
Pregunta 10
Pregunta
ignore untrusted certificates is only available if Multiple Clients Connecting to Multiple _ Servers is selected
Respuesta
True
False
Pregunta 11
Pregunta
CSR
Respuesta
Certificate signing request
Certificate security request
Pregunta 12
Pregunta
Deleting a CSR that is a pending state does not impact your ability to install the certificate.
Respuesta
A. True
B. False
Pregunta 13
Pregunta
What is one reason why a CA would trust and accept a CSR from a FortiGate?
Respuesta
A. The CSR is signed by the FortiGate’s private key.