Q: 6
An administrator must minimize CPU and RAM use on a FortiGate firewall while also enabling
essential security features, such as web filtering and application control for HTTPS traffic.
Which SSL inspection setting helps reduce system load while also enabling security features, such as
web filtering and application control for encrypted HTTPS traffic?
Options
Discussion
D , certificate inspection mode uses way less resources and still gets the job done for filtering HTTPS traffic.
D imo. Certificate inspection does enough for web filtering and app control by checking certs and SNI, without chewing up resources like full SSL inspection. You lose some deep inspection, but that's the tradeoff for saving CPU/RAM. Seen similar wording on practice tests-D's the efficient option here.
C tbh, since it says 'handle HTTPS traffic efficiently' and that sounds like a resource-saving mode. I thought certificate inspection (D) is too basic and might not support all security features, but maybe I'm missing something. Can someone clarify the main difference here?
D or maybe C, but pretty sure it's D. Certificate inspection mode checks just the cert info and SNI, so it supports URL filtering/app control with way less CPU/RAM use than full inspection. Clear question, nice to see specifics called out here.
Be respectful. No spam.