Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their browser displays a warning saying…

A user reports that their browser displays a warning saying 'Your connection is not private' when visiting a frequently used banking site. After checking, you see the certificate error is for a different domain. What is the most likely cause?

⚠ Common exam trap

CompTIA often tests the distinction between certificate errors caused by date/time issues versus domain mismatches, and the trap here is that candidates may confuse a 'different domain' error with a simple expired certificate or browser update issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A malicious proxy or DNS hijacking is redirecting traffic to a fake site

The certificate error for a different domain indicates that the browser is being directed to a server whose SSL certificate does not match the expected banking site's domain. This is a classic sign of a man-in-the-middle attack, often caused by malicious proxy or DNS hijacking, where traffic is redirected to a fraudulent server presenting a certificate for a different domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The user's system date and time are incorrect

    Why it's wrong here

    An incorrect system date and time can indeed cause browser warnings related to SSL/TLS certificates. Browsers check the certificate's validity period against the system's clock, and if the clock is outside this range, the certificate will appear invalid. However, this specific issue would typically result in a "certificate not yet valid" or "certificate expired" error for the intended domain, not a warning indicating that the certificate is for a different domain entirely.

  • The website's SSL certificate has expired

    Why it's wrong here

    If a website's SSL certificate has expired, the browser will display a warning indicating that the certificate is no longer valid. This is because the certificate's cryptographic trust period has elapsed, and it can no longer be verified by a Certificate Authority. While this is a serious security warning, it would specifically state that the certificate for the intended domain is expired, not that the certificate presented belongs to an entirely different domain name.

  • A malicious proxy or DNS hijacking is redirecting traffic to a fake site

    Why this is correct

    A malicious proxy or DNS hijacking attack can redirect a user's traffic from the legitimate website to a fraudulent, imposter site controlled by an attacker. When the browser attempts to establish an HTTPS connection with this fake site, the attacker presents an SSL certificate that either belongs to a completely different domain or is self-signed and untrusted. This mismatch between the expected domain and the domain listed on the presented certificate is a strong indicator of a man-in-the-middle attack, alerting the user to potential data interception or phishing.

  • The browser needs to be updated to the latest version

    Why it's wrong here

    While keeping a browser updated is crucial for security, an outdated browser version is unlikely to be the direct cause of a certificate domain mismatch warning. Browser updates primarily address security vulnerabilities, improve performance, and add support for new web standards or cryptographic protocols. An older browser might fail to trust newer certificates or display general security warnings, but it would not inherently cause a legitimate website's certificate to appear as if it belongs to a completely different, unrelated domain.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.