QuestionQ12

Security profiles

Refer to the exhibit.

Question Image

The packet-capture output for a ClientHello message is displayed.

You are updating a firewall policy that includes SSL certificate inspection. You are capturing packets from traffic traversing this firewall policy.

Which two statements about the packet capture are correct?

Choose two
  • A The subject alternative name (SAN) is necessary to apply security profiles.
  • B The client support only TLS versions 1.2 and 1.3.
  • C You can effectively apply a web filtering profile to this traffic.
  • D You can effectively apply an antivirus security profile to this traffic.
Explanation

The ClientHello supported_versions extension advertises TLS 1.3 and TLS 1.2. SSL certificate inspection examines TLS-layer headers and certificate-related information, including the hostname information available for controlling website access, so a web-filtering profile can be effective. It does not inspect the encrypted traffic payload, so it cannot effectively perform antivirus content scanning. A SAN is not a prerequisite for applying security profiles.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!