nerdexam
CompTIA

CAS-003 · Question #920

A company deploys a system to use device and user certificates for network authentication. Previously, the company only used separate certificates to send receive encrypted email. Users have begun…

The correct answer is A. The attestation service is not configured to accept the new certificates. When the company deployed new device and user certificates for network authentication, the attestation service-responsible for validating certificate authenticity and trust-was not updated to recognize or trust the newly issued certificates. S/MIME encrypted email relies on the…

Technical Integration of Enterprise Security

Question

A company deploys a system to use device and user certificates for network authentication. Previously, the company only used separate certificates to send receive encrypted email. Users have begun notifying the help desk because they cannot read encrypted email. Which of the following is the MOST likely cause of the issues7

Options

  • AThe attestation service is not configured to accept the new certificates.
  • BThe device certificates have the S/MIME attribute selected
  • CThe sending mail client is selecting the wrong public key to encrypt messages
  • DMultiple device certificates are associated with the same network port

How the community answered

(40 responses)
  • A
    53% (21)
  • B
    8% (3)
  • C
    25% (10)
  • D
    15% (6)

Explanation

When the company deployed new device and user certificates for network authentication, the attestation service-responsible for validating certificate authenticity and trust-was not updated to recognize or trust the newly issued certificates. S/MIME encrypted email relies on the same PKI infrastructure to validate recipient certificates when decrypting messages. Because the attestation service was not configured to accept the new certificates, the validation of those certificates fails during email decryption, causing users to be unable to read encrypted messages. The other options are less likely: Option B would affect email signing/encryption behavior but device certs shouldn't have S/MIME attributes selected if they're for network auth; Option C is plausible but implies a client-side misconfiguration rather than a systemic infrastructure problem; Option D relates to port binding which is unrelated to certificate validation.

Topics

#PKI#S/MIME#certificate management#email encryption

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice