hardMultiple Choice
200-901 Uses a private Docker registry with TLS Practice Question
An organization uses a private Docker registry with TLS. A developer attempts to pull an image and receives the error: "x509: certificate signed by unknown authority". What is the most likely cause and solution?
⚠ Common exam trap
Candidates often confuse a certificate trust issue with a hostname mismatch or think disabling TLS is an acceptable workaround, but Cisco specifically tests the understanding that the correct enterprise-grade fix is to trust the CA, not to weaken security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the CA certificate to the client's trust store
The error 'x509: certificate signed by unknown authority' occurs because the Docker client does not recognize the certificate authority (CA) that signed the registry's TLS certificate. The correct solution is to add the CA certificate to the client's trust store, typically by placing it in /etc/docker/certs.d/<registry_hostname>:<port>/ca.crt on Linux or the equivalent Docker certs directory on other platforms. This allows the Docker daemon to validate the registry's certificate during the TLS handshake.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the CA certificate to the client's trust store
Why this is correct
The x509 error means the registry's certificate chains to a CA absent from the client's trust store. Installing that CA certificate into the Docker daemon's trusted certificates directory lets the client validate the registry's TLS chain, resolving the pull failure described in the stem.
- ✗
Use the registry's IP address instead of hostname
Why it's wrong here
Swapping the hostname for an IP address does not make the client trust the signing CA, and the certificate's subject would no longer match. It is tempting because name resolution issues do cause pull failures, so it is the right fix when DNS, not trust, is the actual problem.
- ✗
Disable TLS verification on the client
Why it's wrong here
Disabling TLS verification removes the trust check rather than installing the registry's CA, leaving the connection open to interception. It is tempting because it makes the error disappear immediately, and is acceptable only in isolated lab environments where no sensitive images or credentials are involved.
- ✗
Use HTTP instead of HTTPS
Why it's wrong here
Falling back to HTTP drops transport encryption entirely and Docker still refuses plaintext to a registry it does not trust. It is tempting because it sidesteps certificate handling, and is valid only for a deliberately configured insecure local registry on a trusted loopback network.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.