Courseiva
Network SecurityhardMultiple ChoiceObjective-mapped

350-701 Network Security Practice Question

An engineer is deploying a Cisco FTD in inline mode and wants to inspect SSL/TLS traffic using the 'decrypt-resign' action. What must be configured on the client devices to avoid certificate errors?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Install the organization's CA certificate in the client's trusted root store.

When using 'decrypt-resign', the FTD generates a new certificate signed by a CA that the organization controls. Clients must trust the organization's CA certificate (root CA) that is used to sign the re-encrypted certificates. Without that, clients will see certificate errors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable certificate validation on all client browsers.

    Why it's wrong here

    This is not a secure or scalable solution.

  • Install the organization's CA certificate in the client's trusted root store.

    Why this is correct

    This ensures the re-signed certificates are trusted.

  • Install the FTD's self-signed certificate on each client.

    Why it's wrong here

    Self-signed certificates are not trusted by default; a CA-trusted certificate is needed.

  • Use 'decrypt-known-key' instead, which does not require client configuration.

    Why it's wrong here

    Known-key decrypt still requires the server's private key and may not be feasible.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.