NSE7_EFW Security And VPN Practice Question
A network administrator is configuring SSL inspection for a group of users. Which certificate must be installed on the client endpoints to prevent browser certificate warnings?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate CA certificate used for SSL inspection
The FortiGate acts as a man-in-the-middle, so the client must trust the CA certificate generated by the FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The FortiGate CA certificate used for SSL inspection
Why this is correct
Clients must trust the CA that signs the re-issued certificates.
- ✗
The FortiGate's local device certificate
Why it's wrong here
This is for HTTPS management access.
- ✗
The Fortinet_Factory CA certificate
Why it's wrong here
This is for internal device identity, not inspection.
- ✗
A third-party public CA certificate
Why it's wrong here
Public CAs are for public websites, not internal inspection proxies.
About these practice questions
This NSE7_EFW question is part of Courseiva's 91-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Fortinet exam blueprint
This NSE7_EFW practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7_EFW exam.