問題文
Which statements correctly describe the forward trust and forward untrust certificates used for outbound decryption? (Select two.)
選択肢
- The forward untrust certificate is used instead when validation of the server certificate fails, so the user sees a warning.
- Both certificates are presented to the server so that the server can decide whether the firewall is allowed to inspect the session.
- The forward trust certificate is used to re-sign the server certificate when the firewall could validate the original server certificate.
- The forward trust certificate is the same object as the certificate presented by the firewall's own web interface.
- The forward untrust certificate must be installed in the trust store of every endpoint, otherwise the firewall cannot complete the session at all and the user is unable to reach the site even after acknowledging a warning.