nerdexam
CompTIA

220-1002 · Question #203

A small office calls a technician to investigate some "invalid certificate" errors from a concerned user. The technician observes that whenever the user to access a secure website from the Windows…

The correct answer is A. Remove any proxy servers configured on the user's browsers. F. Run anti-malware scans and download the latest Windows updates. Since only this one user is affected, the issue is isolated to their workstation or browser configuration. Removing proxy server settings (A) is critical because a misconfigured or malicious proxy can perform a man-in-the-middle (MITM) attack, intercepting HTTPS traffic and…

Networking

Question

A small office calls a technician to investigate some "invalid certificate" errors from a concerned user. The technician observes that whenever the user to access a secure website from the Windows desktop, this error is encountered. No other users in the office are experiencing this error. Which of the following should the technician do NEXT? (Choose two.)

Options

  • ARemove any proxy servers configured on the user's browsers.
  • BAssist the user with purchasing an SSL certificate and save the certificate to the desktop.
  • CDisable the SPI firewall on the office's gateway and any other routers.
  • DInstruct the user to ignore the certificate error since the user is connecting to a secure website.
  • ECreate an outbound rule in Windows Firewall named after the user's homepage.
  • FRun anti-malware scans and download the latest Windows updates.

How the community answered

(23 responses)
  • A
    52% (12)
  • B
    26% (6)
  • C
    13% (3)
  • D
    4% (1)
  • E
    4% (1)

Explanation

Since only this one user is affected, the issue is isolated to their workstation or browser configuration. Removing proxy server settings (A) is critical because a misconfigured or malicious proxy can perform a man-in-the-middle (MITM) attack, intercepting HTTPS traffic and presenting its own self-signed certificate, causing invalid certificate warnings. Running anti-malware scans and applying the latest Windows updates (F) addresses the possibility that malware has tampered with the browser's certificate store or is actively intercepting traffic. Buying an SSL certificate (B) is irrelevant - that is for web server administrators, not end users. Disabling the SPI firewall (C) would reduce security and is unnecessary. Ignoring certificate errors (D) is dangerous as it could expose the user to real MITM attacks. Creating a Windows Firewall outbound rule (E) has no bearing on certificate validation.

Topics

#SSL certificates#proxy settings#malware#browser security

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice