nerdexam
CompTIA

CAS-005 · Question #268

A company migrating to a remote work model requires that company-owned devices connect to a VPN before logging in to the device itself. The VPN gateway requires that a specific key extension is…

The correct answer is B. The VPN client selected the certificate with the correct key usage without user interaction. This scenario describes an enterprise VPN setup that requires machine authentication before a user logs in. The best explanation for this requirement is that the VPN client selects the appropriate certificate automatically based on the key extension in the machine certificate…

Submitted by kim_seoul· Mar 6, 2026Security Engineering

Question

A company migrating to a remote work model requires that company-owned devices connect to a VPN before logging in to the device itself. The VPN gateway requires that a specific key extension is deployed to the machine certificates in the internal PKI. Which of the following best explains this requirement?

Options

  • AThe certificate is an additional factor to meet regulatory MFA requirements for VPN access.
  • BThe VPN client selected the certificate with the correct key usage without user interaction.
  • CThe internal PKI certificate deployment allows for Wi-Fi connectivity before logging in to other
  • DThe server connection uses SSL VPN, which uses certificates for secure communication.

How the community answered

(37 responses)
  • A
    16% (6)
  • B
    73% (27)
  • C
    8% (3)
  • D
    3% (1)

Explanation

This scenario describes an enterprise VPN setup that requires machine authentication before a user logs in. The best explanation for this requirement is that the VPN client selects the appropriate certificate automatically based on the key extension in the machine certificate. Understanding the Key Extension Requirement: PKI (Public Key Infrastructure) issues machine certificates that include specific key usages such as Client Authentication or IPSec IKE Intermediate. Key usage extensions define how a certificate can be used, ensuring that only valid certificates are selected by the VPN client.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice