mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: That their browser displays a warning saying…
A user reports that their browser displays a warning saying 'Your connection is not private' when visiting a frequently used banking site. After checking, you see the certificate error is for a different domain. What is the most likely cause?
⚠ Common exam trap
CompTIA often tests the distinction between certificate errors caused by date/time issues versus domain mismatches, and the trap here is that candidates may confuse a 'different domain' error with a simple expired certificate or browser update issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A malicious proxy or DNS hijacking is redirecting traffic to a fake site
The certificate error for a different domain indicates that the browser is being directed to a server whose SSL certificate does not match the expected banking site's domain. This is a classic sign of a man-in-the-middle attack, often caused by malicious proxy or DNS hijacking, where traffic is redirected to a fraudulent server presenting a certificate for a different domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's system date and time are incorrect
Why it's wrong here
An incorrect system date and time can indeed cause browser warnings related to SSL/TLS certificates. Browsers check the certificate's validity period against the system's clock, and if the clock is outside this range, the certificate will appear invalid. However, this specific issue would typically result in a "certificate not yet valid" or "certificate expired" error for the intended domain, not a warning indicating that the certificate is for a different domain entirely.
- ✗
The website's SSL certificate has expired
Why it's wrong here
If a website's SSL certificate has expired, the browser will display a warning indicating that the certificate is no longer valid. This is because the certificate's cryptographic trust period has elapsed, and it can no longer be verified by a Certificate Authority. While this is a serious security warning, it would specifically state that the certificate for the intended domain is expired, not that the certificate presented belongs to an entirely different domain name.
- ✓
A malicious proxy or DNS hijacking is redirecting traffic to a fake site
Why this is correct
A malicious proxy or DNS hijacking attack can redirect a user's traffic from the legitimate website to a fraudulent, imposter site controlled by an attacker. When the browser attempts to establish an HTTPS connection with this fake site, the attacker presents an SSL certificate that either belongs to a completely different domain or is self-signed and untrusted. This mismatch between the expected domain and the domain listed on the presented certificate is a strong indicator of a man-in-the-middle attack, alerting the user to potential data interception or phishing.
- ✗
The browser needs to be updated to the latest version
Why it's wrong here
While keeping a browser updated is crucial for security, an outdated browser version is unlikely to be the direct cause of a certificate domain mismatch warning. Browser updates primarily address security vulnerabilities, improve performance, and add support for new web standards or cryptographic protocols. An older browser might fail to trust newer certificates or display general security warnings, but it would not inherently cause a legitimate website's certificate to appear as if it belongs to a completely different, unrelated domain.
Go deeper
Related to this question
Learn chapter
Windows User Accounts and Groups
Key term
Man-in-the-middle attack
A cyberattack where an attacker secretly intercepts and potentially alters communication between two parties who believe they are directly communicating with each other.
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.