Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?

⚠ Common exam trap

The trap here is assuming that a certificate warning always means the website's certificate is expired or misconfigured, rather than considering an on-path attacker presenting a fraudulent certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The certificate chain presented by the browser to see if it is issued by an unknown or self-signed certificate authority.

The certificate chain is the most direct evidence of an on-path attack because the attacker must present a certificate to intercept TLS traffic. If the certificate is self-signed or issued by an untrusted CA, the browser will warn the user. DNS or ARP checks might reveal other attack vectors, but the certificate warning specifically indicates TLS interception, so examining the certificate chain confirms the attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The DNS server settings on the user's device and compare them to the corporate DNS servers.

    Why it's wrong here

    Comparing DNS settings could reveal a rogue DNS server, but an on-path attacker typically intercepts traffic without changing DNS settings. The certificate warning indicates the attacker is intercepting TLS connections, not necessarily redirecting DNS. Checking DNS first is less direct than examining the certificate chain, which would immediately show the attacker's certificate.

  • ✓

    The certificate chain presented by the browser to see if it is issued by an unknown or self-signed certificate authority.

    Why this is correct

    An on-path attack often involves a self-signed or rogue CA certificate to intercept TLS traffic. Inspecting the certificate chain will reveal if the certificate is not issued by a trusted CA, confirming interception. This is the most direct evidence of an on-path attack, as the attacker must present a certificate to decrypt traffic, and it will not be trusted by the user's device.

  • ✗

    The ARP cache on the user's device to look for duplicate MAC addresses.

    Why it's wrong here

    Checking the ARP cache can detect ARP poisoning, which is a common on-path attack method on local networks. However, the user is at a coffee shop on Wi-Fi, where ARP spoofing is less likely due to network segmentation, and the certificate warning directly points to TLS interception. The ARP cache might show the gateway's MAC, but that alone does not confirm an on-path attack on TLS.

  • ✗

    The Wi-Fi encryption type configured on the user's device to ensure it is using WPA3.

    Why it's wrong here

    Wi-Fi encryption type affects the wireless link between the device and access point, but an on-path attack can occur even with strong encryption if the attacker controls the access point or uses a rogue AP. The certificate warning is at the TLS layer, not the wireless layer. Checking WPA3 settings would not confirm the presence of an on-path attack and is not the first step.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.