nerdexam
Cisco

200-201 · Question #492

Refer to the exhibit. Which set of actions must an engineer perform to identify and fix this issue?

The correct answer is D. Add client authentication to the certificate template, reissue, and apply the certificate. The error message indicates that the certificate in use does not have SSL Client Authentication capabilities. This means that the certificate lacks the necessary Extended Key Usage (EKU) attribute required for authentication. To fix this issue, the engineer must update the…

Submitted by amina.ke· Mar 6, 2026Host-Based Analysis

Question

Refer to the exhibit. Which set of actions must an engineer perform to identify and fix this issue?

Exhibit

200-201 question #492 exhibit

Options

  • AReinstall the IIS server to reset certificate details to default and try to connect to the server.
  • BRemove the intermediate certificates and install the CA root certificate on each server.
  • CImplement a different version of CA authority and install intermediate certificates.
  • DAdd client authentication to the certificate template, reissue, and apply the certificate.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    11% (3)
  • D
    75% (21)

Explanation

The error message indicates that the certificate in use does not have SSL Client Authentication capabilities. This means that the certificate lacks the necessary Extended Key Usage (EKU) attribute required for authentication. To fix this issue, the engineer must update the certificate template to include Client Authentication, reissue the certificate, and apply it to the affected system. This ensures that the certificate meets the authentication requirements for ConfigMgr

Topics

#certificate management#client authentication#PKI#server configuration

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice