Q: 6
An administrator must minimize CPU and RAM use on a FortiGate firewall while also enabling
essential security features, such as web filtering and application control for HTTPS traffic.
Which SSL inspection setting helps reduce system load while also enabling security features, such as
web filtering and application control for encrypted HTTPS traffic?
Options
Discussion
D . Cert inspection mode barely touches CPU/RAM since it skips decrypting everything, but you can still do domain-based filtering and app control on HTTPS. Full SSL would kill performance. Pretty sure this is what they’re asking but open to pushback.
C vs D here. C sounds right at first with the 'efficient' bit, but it's vague and doesn't mean a specific FortiGate setting. D is literal-certificate inspection mode is way less resource-heavy and still does basic HTTPS filtering. Pretty sure D is what the exam wants, but I get why C looks tempting.
C/D? C talks about handling HTTPS "efficiently," which kinda fits the resource-saving part, and some questions use wording tricks like that. D is correct for cert inspection, but C felt like a trap here.
Yeah, D fits here. You keep basic filtering and app control without the decrypt overhead.
D , certificate inspection mode uses way less resources and still gets the job done for filtering HTTPS traffic.
D imo. Certificate inspection does enough for web filtering and app control by checking certs and SNI, without chewing up resources like full SSL inspection. You lose some deep inspection, but that's the tradeoff for saving CPU/RAM. Seen similar wording on practice tests-D's the efficient option here.
Why does C keep coming up? On FortiGate, "efficient HTTPS handling" isn't an actual setting, it's just vague wording.
Pretty sure it's D. Certificate inspection mode checks the SNI and cert without full decryption, which keeps resource usage low but still lets you do web filtering on HTTPS. C sounds reasonable, but it's too generic and not a real FortiGate config option. Anyone see a scenario where C would actually be correct?
D (seen similar on practice, always certificate inspection for low system use with required HTTPS filtering)
C tbh, since it's the only one mentioning handling HTTPS efficiently, that sounds right for saving resources.
Be respectful. No spam.