Marcos Avila
Quiz by , created more than 1 year ago

NSE4 6.0 NSE4 6.0 Quiz on Certificate Operations, created by Marcos Avila on 16/08/2018.

189
1
0
Marcos Avila
Created by Marcos Avila over 5 years ago
Close

Certificate Operations

Question 1 of 13

1

FortiGate uses the ______ certificate standard.

Select one of the following:

  • X.509v3

  • X.509v4

  • X.509v5

Explanation

Question 2 of 13

1

What attribute or extension is used to identify the owner of a certificate?

Select one of the following:

  • a. The subject name in the certificate

  • b. The unique serial number in the certificate

Explanation

Question 3 of 13

1

How does FortiGate check to see if a certificate has been revoked?

Select one of the following:

  • a. It checks the CRL that resides on FortiGate.

  • b. It retrieves the CRL from a directory server.

Explanation

Question 4 of 13

1

Which one of the following is a certificate extension and value that is required in the FortiGate CA certificate in order to enable full SSL inspection?

Select one of the following:

  • a. CRL DP=ca_arl.arl

  • b. cA=True

Explanation

Question 5 of 13

1

For full SSL inspection, which configuration requires FortiGate to act as a CA?

Select one of the following:

  • a. Multiple clients connecting to multiple servers

  • b. Protecting the SSL server

Explanation

Question 6 of 13

1

Deleting a CSR that is a pending state does not impact your ability to install the certificate.

Select one of the following:

  • a. True

  • b. False

Explanation

Question 7 of 13

1

What is one reason why a CA would trust and accept a CSR from a FortiGate?

Select one of the following:

  • a. The CSR is signed by the FortiGate’s private key.

  • b. The CA inherently trusts all FortiGates.

Explanation

Question 8 of 13

1

To be compliant with the Internet Engineering Task Force (IETF) RFC 5280, the CA certificate requires these two extensions to issue certificates:

Select one of the following:

  • cA=True
    keyUsage=keyCertSign

  • cA=True
    RFC=5280

Explanation

Question 9 of 13

1

Untrusted SSL Certificates options: (select 3)

Select one or more of the following:

  • Allow

  • Block

  • Ignore

  • Log only

  • Default

  • Quarantine

Explanation

Question 10 of 13

1

ignore untrusted certificates is only available if Multiple Clients Connecting to Multiple _ Servers is selected

Select one of the following:

  • True
  • False

Explanation

Question 11 of 13

1

CSR

Select one of the following:

  • Certificate signing request

  • Certificate security request

Explanation

Question 12 of 13

1

Deleting a CSR that is a pending state does not impact your ability to install the certificate.

Select one of the following:

  • A. True

  • B. False

Explanation

Question 13 of 13

1

What is one reason why a CA would trust and accept a CSR from a FortiGate?

Select one of the following:

  • A. The CSR is signed by the FortiGate’s private key.

  • B. The CA inherently trusts all FortiGates.

Explanation