Refer to the exhibit.

Given the exhibit, which two statements about FortiGate FGSP HA cluster behavior are correct? (Choose two.)
Bis correct because the OCSP check of the certificate can be combined with a certificate revocation list (CRL). This means that the FortiGate will check the OCSP server to see if the certificate has been revoked, and it will also check the CRL to see if the certificate has been revoked.
Dis correct because if the OCSP server is unreachable, authentication will succeed if the certificate matches the CA. This is because the FortiGate will fall back to using the CRL if the OCSP server is unreachable.
The other options are incorrect. Option A is incorrect because OCSP checks can go to other OCSP servers, not just the FortiAuthenticator. Option C is incorrect because OCSP certificate responses can be cached by the FortiGate.
References:
Configuring SSL VPN authentication using digital certificates | FortiGate / FortiOS 7.2.0 - Fortinet Document Library
Online Certificate Status Protocol (OCSP) | FortiGate / FortiOS 7.2.0 - Fortinet Document Library
Certificate Revocation Lists (CRLs) | FortiGate / FortiOS 7.2.0 - Fortinet Document Library
Tracie
4 months agoNikita
4 months agoReita
4 months agoHarris
4 months agoKate
5 months agoIesha
5 months agoJustine
5 months agoEsteban
5 months agoRoslyn
5 months agoJudy
5 months agoDarci
5 months agoMelissa
5 months agoMattie
5 months agoAdell
5 months agoHector
10 months agoFelicitas
9 months agoLoren
9 months agoMerissa
10 months agoTracey
11 months agoLorrie
10 months agoLanie
10 months agoGeorgiann
10 months agoMaryann
11 months agoChana
11 months agoJaney
10 months agoRyan
10 months agoHolley
10 months agoLenna
11 months agoShad
11 months agoHeidy
10 months agoAnglea
10 months agoParis
11 months agoMatthew
11 months agoKristine
11 months ago