Setting unsupported-ssl-version to block prevents HTTPS connections from continuing when the negotiated SSL/TLS version falls below the version permitted by the inspection profile. The Enterprise Firewall 7.6 Administrator Study Guide demonstrates this hardening control together with an appropriate minimum version and explains that it can block obsolete TLS versions while accepting newer, secure versions. Therefore, option A is correct.
Enabling Server certificate SNI check protects against hostname inconsistencies between the client-supplied SNI and the server certificate. The FortiOS guide explains that, when enabled, FortiGate uses the certificate’s CN when the SNI hostname does not match any CN or SAN entry. This reduces the risk of SNI-based filtering evasion or domain-fronting behavior, making option B correct.
Setting untrusted certificates to Ignore weakens security. FortiGate proceeds with the SSL session regardless of whether the server certificate is trusted. Option C is therefore incorrect.
SSL 3.0 is obsolete and vulnerable, including exposure to POODLE-style attacks. Setting it as the minimum permitted version does not constitute secure hardening. A hardened profile should normally require TLS 1.2 or later, so option D is incorrect.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit