Question 5
Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)
SSL inspection and authentication policy
Correct answer: CD
Explanation:
"NGFW policy based mode, you must configure a few policies to allow traffic: SSL inspection & Authentication, Security policy"Security policies work with SSL Inspection & Authentication policies to inspect traffic. To allow traffic from a specific user or user group,both Security and SSL Inspection & Authentication policies must be configured. Reference: https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-modehttps://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/978598/profile-based-ngfw-vs-policy-based-ngfw
"NGFW policy based mode, you must configure a few policies to allow traffic: SSL inspection & Authentication, Security policy"Security policies work with SSL Inspection & Authentication policies to inspect traffic. To allow traffic from a specific user or user group,both Security and SSL Inspection & Authentication policies must be configured.
Reference:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/38324/ngfw-policy-based-mode
https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/978598/profile-based-ngfw-vs-policy-based-ngfw