200-901 Application Deployment and Security Practice Question
A developer is building a microservice that must call an internal API. The API uses mutual TLS (mTLS), and the service must validate the server certificate against a private CA. Which configuration should the client use to verify the server identity?
⚠ Common exam trap
The trap here is believing that mutual TLS only requires the client to present a certificate, when the client must also validate the server's certificate chain and hostname.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Load the private CA certificate into the client's trust store and set the server name for hostname verification.
Verifying a server certificate against a private CA requires the client to trust that CA and to check the server name against the certificate's identity. Presenting a client certificate alone only authenticates the client, and disabling validation or pinning the leaf certificate does not provide the required chain validation. Trusting the private CA and enforcing hostname verification satisfies the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Present the client certificate and private key, and skip server certificate validation because mTLS is mutual.
Why it's wrong here
Presenting a client certificate satisfies the server's authentication of the client, but it does not validate the server. Mutual authentication requires both directions to verify each other. Skipping server validation means the client cannot confirm it is talking to the legitimate API, so this option fails the stated requirement.
- ✗
Disable certificate verification and rely on the private network boundary for trust.
Why it's wrong here
Disabling verification defeats mTLS and allows any certificate, including an attacker's, to be accepted. A private network boundary is not a substitute for cryptographic identity verification, and it enables man-in-the-middle attacks from within the network. This directly contradicts the requirement to validate the server against the private CA.
- ✗
Pin the server's leaf certificate by comparing its fingerprint on every connection.
Why it's wrong here
Certificate pinning can detect changes, but pinning the leaf certificate breaks whenever the server rotates its certificate, which is common with short-lived certs. It also does not validate the chain against the private CA. While pinning has uses, the scenario asks for CA-based verification, making this approach brittle and misaligned.
- ✓
Load the private CA certificate into the client's trust store and set the server name for hostname verification.
Why this is correct
mTLS requires the client to validate the server certificate chain. Trusting the private CA allows the client to verify the chain, and setting the expected server name enforces hostname verification against the certificate's subject alternative name. This provides both chain validation and identity binding, which is exactly what the scenario requires.
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.