Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE6_FAC-6.4 Topic 5 Question 33 Discussion

Actual exam question for Fortinet's NSE6_FAC-6.4 exam
Question #: 33
Topic #: 5
[All NSE6_FAC-6.4 Questions]

Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

Show Suggested Answer Hide Answer
Suggested Answer: A, B

CRLs are lists of certificates that have been revoked by the issuing CA and should not be trusted by any entity. CRLs contain the serial number of the certificate that has been revoked, the date and time of revocation, and the reason for revocation. Revoked certificates are automatically placed on the CRL by the CA and the CRL is updated periodically. CRLs can be exported through various methods, such as HTTP, LDAP, or SCEP. Each local CA has its own CRL that is specific to its issued certificates. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372408/certificate-management/372413/certificate-revocation-lists


Contribute your Thoughts:

Tammara
3 months ago
I'm not sure about C and D, but A and B seem like the most logical choices for CRL behaviors.
upvoted 0 times
...
Izetta
3 months ago
I agree with Colby. A makes sense because CRLs should contain the serial number of revoked certificates.
upvoted 0 times
...
Mose
4 months ago
C is a bit misleading. CRLs can be exported through other means, not just the SCEP server.
upvoted 0 times
Alisha
2 months ago
C is a bit misleading. CRLs can be exported through other means, not just the SCEP server.
upvoted 0 times
...
Danica
2 months ago
D) All local CAs share the same CRLs
upvoted 0 times
...
Mattie
2 months ago
B) Revoked certificates are automatically placed on the CRL
upvoted 0 times
...
Lai
3 months ago
A) CRLs contain the serial number of the certificate that has been revoked
upvoted 0 times
...
...
Nickie
4 months ago
Haha, 'automaticlly' in option B - I bet the exam writers had a little chuckle over that one!
upvoted 0 times
Melvin
3 months ago
Haha, 'automaticlly' in option B - I bet the exam writers had a little chuckle over that one!
upvoted 0 times
...
Glen
3 months ago
B) Revoked certificates are automaticlly placed on the CRL
upvoted 0 times
...
Rachael
3 months ago
A) CRLs contain the serial number of the certificate that has been revoked
upvoted 0 times
...
...
Colby
4 months ago
I think A and B are the correct behaviors for CRLs on FortiAuthenticator.
upvoted 0 times
...
Leonora
4 months ago
D is definitely wrong - each local CA should have its own unique CRL, not a shared one.
upvoted 0 times
Norah
3 months ago
Yes, D is incorrect. Each local CA should have its own unique CRL.
upvoted 0 times
...
Tamar
3 months ago
D) All local CAs share the same CRLs
upvoted 0 times
...
Myra
3 months ago
B) Revoked certificates are automatically placed on the CRL
upvoted 0 times
...
Gretchen
3 months ago
A is correct, but what about B?
upvoted 0 times
...
Coral
3 months ago
C) CRLs can be exported only through the SCEP server
upvoted 0 times
...
Lavonne
3 months ago
B) Revoked certificates are automatically placed on the CRL
upvoted 0 times
...
Markus
4 months ago
A) CRLs contain the serial number of the certificate that has been revoked
upvoted 0 times
...
...
Nickolas
4 months ago
A and B seem like the correct options here. Revoking certificates and including them in the CRL is a standard practice.
upvoted 0 times
Patti
4 months ago
Yes, A) CRLs contain the serial number of the certificate that has been revoked and B) Revoked certificates are automatically placed on the CRL.
upvoted 0 times
...
Patti
4 months ago
I agree, A and B are the correct options for behaviors of CRLs on FortiAuthenticator.
upvoted 0 times
...
...

Save Cancel