220-1102 Security Practice Question
A technician is working on a reception PC and needs to troubleshoot a certificate warning for an internal site. Which two actions are appropriate? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse a certificate warning with a network connectivity issue and jump to hardware replacement, or they may think sharing credentials is a quick fix, but the exam tests adherence to proper troubleshooting methodology and security protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
certificate trust chain review
A certificate warning typically indicates a problem with the certificate's trust chain, such as an untrusted root CA, an expired intermediate certificate, or a missing certificate. Reviewing the trust chain allows the technician to identify whether the certificate is self-signed, issued by an internal CA that isn't trusted by the client, or has a broken chain. This is a standard troubleshooting step for PKI-related issues in internal web applications. Option C is also correct because documenting the observed symptoms and the change made in the ticket is part of the standard troubleshooting methodology—it ensures a record of the issue and resolution for future reference and maintains accountability. Options A and D are inappropriate: performing unrelated hardware replacement wastes time and does not address the certificate warning, while sharing credentials violates security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform an unrelated hardware replacement before testing
Why it's wrong here
Hardware replacement cannot resolve a certificate warning, which stems from trust-chain or expiry issues on the internal site's TLS certificate. It is tempting because swapping components is a familiar first-line fix for boot or display faults, but here it consumes time without touching the certificate store or validation path.
- ✓
certificate trust chain review
Why this is correct
Reviewing the certificate trust chain identifies whether the internal site's certificate is self-signed, expired or issued by an untrusted intermediate CA. This pinpoints the exact validation failure causing the warning, rather than guessing at unrelated causes such as DNS or browser settings.
- ✓
Document the observed symptoms and the change made in the ticket.
Why this is correct
Recording the observed symptoms and the change made preserves an audit trail for the ticket, supporting later root-cause analysis and repeat incidents. This documentation satisfies organisational change and incident-handling requirements, ensuring the resolution is traceable and reproducible.
- ✗
Share administrator credentials with the user for convenience
Why it's wrong here
Sharing administrator credentials breaks accountability and least privilege, and the technician cannot verify who performed privileged actions afterwards. Elevated rights are for the technician's own named account during troubleshooting; convenience never justifies credential sharing, which also breaches most organisational security policies and audit requirements.
Go deeper
Related to this question
Learn chapter
Certificate Management for A+
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Accountability
Accountability is the security principle that ensures actions and identity are linked so that a person or system can be held responsible for their activities.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.