A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?
If the root CA certificate is missing from the Trusted Root Certification Authorities store, the browser cannot build a chain of trust to the site's certificate, producing an untrusted warning. Since the clock and network are fine, removal of the root certificate is the most likely cause. Reinstalling the root CA or using a trusted root update resolves the issue.
Why this answer
A browser trusts a TLS certificate only if it can chain it to a root CA in the Trusted Root Certification Authorities store. If that root was removed, the chain breaks and the browser warns that the certificate is not trusted. An expired certificate or DNS problem could also cause warnings, but the sudden failure with a correct clock points to a missing root certificate.
Exam trap
The trap here is assuming any certificate warning means the site's certificate expired, without considering that a missing root CA also breaks the trust chain.