050-V66-SERCMS02 · Question #3
What extension profile should be used in RSA Certificate Manager when issuing end-entity certificates for secure e-mail?
The correct answer is C. S/MIME v3 User. See the full explanation below for the reasoning.
Question
What extension profile should be used in RSA Certificate Manager when issuing end-entity certificates for secure e-mail?
Options
- AIPSec
- BSSL Client
- CS/MIME v3 User
- DPKIX-Compliant CA
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C77% (20)
- D12% (3)
Community Discussion
4C is the right pick here. The S/MIME v3 User extension profile is designed specifically for end-entity certificates used in secure e-mail, it includes the key usage bits and subject alternative name extensions that S/MIME needs to handle email encryption and digital signatures properly, while the other options cover totally different use cases like VPNs, web auth, or CA certificates.
Exactly right, and to burn it in forever just remember USER equals "U Send Encrypted Replies," because the S/MIME v3 User profile is all about the actual human end-entity doing the sending, never a CA or a VPN box.
Saw this exact one, panicked, then remembered S/MIME v3 User is literally named for secure e-mail.
Okay I almost circled B, SSL Client, because my brain locked onto "secure" and jumped straight to SSL like a reflex, but then I caught myself and remembered the hook: S is for S/MIME, M is for Mail, so S/MIME v3 User literally screams its own job description at you. The PKIX-Compliant CA option is a trap for anyone who half-read the question, because that profile is for issuing CA certificates, not end-entity certs, and D is basically the exam laughing at you. IPSec is your VPN buddy, SSL Client is your browser handshake buddy, but S/MIME v3 User is your inbox buddy, so whenever you see "secure e-mail" plus "end-entity" in the same breath, picture a envelope stamped with a big V3 and you will never miss this one again.