220-1002 · Question #203
A small office calls a technician to investigate some "invalid certificate" errors from a concerned user. The technician observes that whenever the user to access a secure website from the Windows…
The correct answer is A. Remove any proxy servers configured on the user's browsers. F. Run anti-malware scans and download the latest Windows updates. Since only this one user is affected, the issue is isolated to their workstation or browser configuration. Removing proxy server settings (A) is critical because a misconfigured or malicious proxy can perform a man-in-the-middle (MITM) attack, intercepting HTTPS traffic and…
Question
A small office calls a technician to investigate some "invalid certificate" errors from a concerned user. The technician observes that whenever the user to access a secure website from the Windows desktop, this error is encountered. No other users in the office are experiencing this error. Which of the following should the technician do NEXT? (Choose two.)
Options
- ARemove any proxy servers configured on the user's browsers.
- BAssist the user with purchasing an SSL certificate and save the certificate to the desktop.
- CDisable the SPI firewall on the office's gateway and any other routers.
- DInstruct the user to ignore the certificate error since the user is connecting to a secure website.
- ECreate an outbound rule in Windows Firewall named after the user's homepage.
- FRun anti-malware scans and download the latest Windows updates.
How the community answered
(23 responses)- A52% (12)
- B26% (6)
- C13% (3)
- D4% (1)
- E4% (1)
Explanation
Since only this one user is affected, the issue is isolated to their workstation or browser configuration. Removing proxy server settings (A) is critical because a misconfigured or malicious proxy can perform a man-in-the-middle (MITM) attack, intercepting HTTPS traffic and presenting its own self-signed certificate, causing invalid certificate warnings. Running anti-malware scans and applying the latest Windows updates (F) addresses the possibility that malware has tampered with the browser's certificate store or is actively intercepting traffic. Buying an SSL certificate (B) is irrelevant - that is for web server administrators, not end users. Disabling the SPI firewall (C) would reduce security and is unnecessary. Ignoring certificate errors (D) is dangerous as it could expose the user to real MITM attacks. Creating a Windows Firewall outbound rule (E) has no bearing on certificate validation.
Topics
Community Discussion
No community discussion yet for this question.