220-1202 Security Practice Question
A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?
⚠ Common exam trap
The trap here is assuming any certificate warning means the site's certificate expired, without considering that a missing root CA also breaks the trust chain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The root certificate for the issuing CA was removed from the Trusted Root Certification Authorities store.
A browser trusts a TLS certificate only if it can chain it to a root CA in the Trusted Root Certification Authorities store. If that root was removed, the chain breaks and the browser warns that the certificate is not trusted. An expired certificate or DNS problem could also cause warnings, but the sudden failure with a correct clock points to a missing root certificate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's account password has expired.
Why it's wrong here
An expired password affects local or domain logon, not the browser's ability to validate a TLS certificate. The browser warning is about certificate trust, which is independent of user credentials. Password expiration would not cause a certificate trust error on a banking website, so this option is unrelated to the symptom.
- ✓
The root certificate for the issuing CA was removed from the Trusted Root Certification Authorities store.
Why this is correct
If the root CA certificate is missing from the Trusted Root Certification Authorities store, the browser cannot build a chain of trust to the site's certificate, producing an untrusted warning. Since the clock and network are fine, removal of the root certificate is the most likely cause. Reinstalling the root CA or using a trusted root update resolves the issue.
- ✗
The website's TLS certificate has expired.
Why it's wrong here
An expired certificate would also cause a warning, but the scenario states the site worked yesterday and the technician verified the system clock. A certificate that expired overnight is possible, but the question asks for the most likely cause given that the clock is correct and the issue appeared suddenly across a working site. A missing root CA better explains a sudden trust failure.
- ✗
The DNS server is resolving the banking site to an incorrect IP address.
Why it's wrong here
Incorrect DNS resolution could redirect the user to a different server, but that would typically produce a certificate name mismatch rather than a generic untrusted issuer warning. The scenario says the network is functioning, and a DNS issue would more likely affect multiple sites. A missing root CA is the more direct explanation for an untrusted certificate warning.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.