CAS-003 · Question #920
A company deploys a system to use device and user certificates for network authentication. Previously, the company only used separate certificates to send receive encrypted email. Users have begun…
The correct answer is A. The attestation service is not configured to accept the new certificates. When the company deployed new device and user certificates for network authentication, the attestation service-responsible for validating certificate authenticity and trust-was not updated to recognize or trust the newly issued certificates. S/MIME encrypted email relies on the…
Question
A company deploys a system to use device and user certificates for network authentication. Previously, the company only used separate certificates to send receive encrypted email. Users have begun notifying the help desk because they cannot read encrypted email. Which of the following is the MOST likely cause of the issues7
Options
- AThe attestation service is not configured to accept the new certificates.
- BThe device certificates have the S/MIME attribute selected
- CThe sending mail client is selecting the wrong public key to encrypt messages
- DMultiple device certificates are associated with the same network port
How the community answered
(40 responses)- A53% (21)
- B8% (3)
- C25% (10)
- D15% (6)
Explanation
When the company deployed new device and user certificates for network authentication, the attestation service-responsible for validating certificate authenticity and trust-was not updated to recognize or trust the newly issued certificates. S/MIME encrypted email relies on the same PKI infrastructure to validate recipient certificates when decrypting messages. Because the attestation service was not configured to accept the new certificates, the validation of those certificates fails during email decryption, causing users to be unable to read encrypted messages. The other options are less likely: Option B would affect email signing/encryption behavior but device certs shouldn't have S/MIME attributes selected if they're for network auth; Option C is plausible but implies a client-side misconfiguration rather than a systemic infrastructure problem; Option D relates to port binding which is unrelated to certificate validation.
Topics
Community Discussion
No community discussion yet for this question.