156-915.77 · Question #127
(Topic 12) How could you compare the Fingerprint shown to the Fingerprint on the server? Exhibit:
The correct answer is A. Run cpconfig, select the Certificate's Fingerprint option and view the fingerprint. See the full explanation below for the reasoning.
Question
- (Topic 12)
How could you compare the Fingerprint shown to the Fingerprint on the server? Exhibit:
Options
- ARun cpconfig, select the Certificate's Fingerprint option and view the fingerprint
- BRun cpconfig, select the GUI Clients option and view the fingerprint
- CRun cpconfig, select the Certificate Authority option and view the fingerprint
- DRun sysconfig, select the Server Fingerprint option and view the fingerprint
How the community answered
(39 responses)- A74% (29)
- B8% (3)
- C13% (5)
- D5% (2)
Community Discussion
4The answer is A. When you run cpconfig on the Security Management Server, one of the menu options lets you pull up the Certificate's Fingerprint directly, which is exactly what you need to compare against what the SmartConsole client is displaying during that initial connection dialog. That workflow exists precisely for this trust verification step, so an admin can confirm the server they are connecting to is legitimate and not a spoofed system sitting in the middle. Options B and C are in cpconfig but cover completely different functions, GUI client access control and the internal CA, and option D points you to sysconfig which is the wrong tool entirely for this purpose.
Thought D was it but cpconfig, Certificate's Fingerprint option is the move.
Right call, and the quick way to remember it is that the fingerprint in cpconfig is like a wax seal on an envelope, you hold it up and visually match it before you trust the letter, which is exactly what the admin does to verify the gateway identity before SIC trust is established.
I almost picked C thinking "Certificate Authority" sounded right, but cpconfig's Fingerprint option is literally named for this job.