問題文
A company publishes a web application on its own servers and wants the firewall to inspect the requests that arrive from the internet. Which condition must be satisfied for inbound inspection of those encrypted sessions?
選択肢
- The session must terminate on the firewall itself, which then originates a new request to the published server behind it using its own address as the source.
- The firewall must hold the certificate and private key of the published server, because it decrypts the session without acting as an endpoint that the client negotiates with separately.
- The published server must be reconfigured to accept unencrypted connections from the firewall, and the certificate it presents today must be withdrawn from the server, so that inspection can take place.
- Every client on the internet must install and trust a certificate issued by the company, so that the firewall can present its own certificate instead of the one belonging to the published server and can therefore open the session.