(ISC)2
301B · Question #175
301B Question #175: Real Exam Question with Answer & Explanation
Sign in or unlock 301B to reveal the answer and full explanation for question #175. The question stem and answer options stay visible for context.
Question
Refer to the exhibit: A client attempts to connect to from a Google Chrome browser to a virtual server on a BIG-IP LTM. The virtual server is SSL Offloaded. When the client connects, the client receives an SSL error. After trying Mozilla Firefox and Internet Explorer browsers, the client still receives the same errors. The LTM Specialist does an ssldump on the virtual server and receives the results as per the exhibit.
1 1 0.2423 (0.2423) C>S Handshake
Clienthello
Version 3.2
cipher suites
TLS_DHE_RSA_WITH_AES_256_CBC_SHA
TLS_DHE_RSA_WITH_AES_128_CBC_SHA
TLS_DHE_DSS_WITH_AES_256_CBC_SHA
TLS_DHE_DSS_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_RC4_128_SHA
TLS_RSA_WITH_RC4_128_MD5
compression methods
NULL
Unknown SSL content type 72
1 2 0.2432 (0.0009) S<CShort record
1 3 0.2438 (0.0006) C>S TCP FIN
New TCP connection #2: 168.210.232.5(24782) <-> 193.33.229.103(443)
2 1 0.2394 (0.2393) C>S Handshake
Clienthello
Version 3.2
cipher suites
TLS_DHE_RSA_WITH_AES_256_CBC_SHA
TLS_DHE_RSA_WITH_AES_128_CBC_SHA
TLS_DHE_DSS_WITH_AES_256_CBC_SHA
TLS_DHE_DSS_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHA
TLS_RSA_WITH_RC4_128_SHA
TLS_RSA_WITH_RC4_128_MD5
compression methods
NULL
Unknown SSL content type 72
2 2 0.2404 (0.0010) S<CShort record
2 3 0.2404 (0.0000) S<C TCP FIN
2 3 0.4738 (0.2333) C>S Alert
level fatal
value unexpected_message
2 0.4742 (0.0003) C>S TCP FIN
1 3 0.4857 (0.2425) C>S Alert
level fatal
value unexpected_message
1 0.4857 (0.0000) C>S TCP FIN
What is the problem?
Options
- AThe SSL key length is incorrect.
- BThe BIG-IP LTM is NOT serving a certificate.
- CThe BIG-IP LTM is NOT listening on port 443.
- DThe client needs to be upgraded to the appropriate cipher-suite.
Unlock 301B to see the answer
You've previewed enough free 301B questions. Unlock 301B for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.