nerdexam
CompTIA

CAS-003 · Question #606

A remote user reports the inability to authenticate to the VPN concentrator. During troubleshooting, a security administrate captures an attempted authentication and discovers the following being…

The correct answer is B. The user's certificate has been compromised and should be revoked. When a VPN client presents a certificate but authentication still fails, and the scenario implies the certificate appears on a Certificate Revocation List (CRL) or OCSP has flagged it, the most likely cause is that the certificate has been revoked due to compromise. The VPN…

Technical Integration of Enterprise Security

Question

A remote user reports the inability to authenticate to the VPN concentrator. During troubleshooting, a security administrate captures an attempted authentication and discovers the following being presented by the user's VPN client:

Which of the following BEST describes the reason the user is unable to connect to the VPN service?

Exhibit

CAS-003 question #606 exhibit

Options

  • AThe user's certificate is not signed by the VPN service provider
  • BThe user's certificate has been compromised and should be revoked.
  • CThe user's certificate was not created for VPN use
  • DThe user's certificate was created using insecure encryption algorithms

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    83% (24)
  • C
    3% (1)
  • D
    7% (2)

Explanation

When a VPN client presents a certificate but authentication still fails, and the scenario implies the certificate appears on a Certificate Revocation List (CRL) or OCSP has flagged it, the most likely cause is that the certificate has been revoked due to compromise. The VPN concentrator checks certificate validity against the CRL/OCSP and rejects revoked certificates. A certificate not signed by the provider (A) would typically cause a trust chain error. A certificate not created for VPN use (C) would be a key usage/extended key usage mismatch. Weak encryption (D) would cause a cipher negotiation failure, not an authentication rejection.

Topics

#PKI#digital certificates#certificate revocation#VPN authentication

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice