Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is configuring a Linux web server that must accept TLS connections only from clients presenting a valid client certificate issued by the corporate internal CA. The engineer adds `SSLVerifyClient require` to the Apache configuration, restarts the service, and finds that all connections now fail with a handshake error. Which of the following is the MOST likely cause?

⚠ Common exam trap

The trap here is assuming that enabling SSLVerifyClient alone is sufficient, when the server also needs an explicit trust anchor to validate the client chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The `SSLCACertificateFile` directive pointing to the internal CA trust anchor is missing or incorrect.

Requiring client certificates forces the server to build and validate a chain from each client certificate to a trusted anchor. If the CA file that contains the internal root is absent or wrong, every validation fails and the handshake is torn down. Configuring the correct SSLCACertificateFile restores trust and allows valid clients to complete the handshake.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server is missing an OCSP responder URL, so revocation checking fails and the handshake is rejected.

    Why it's wrong here

    Revocation checking via OCSP is not mandatory for a client-certificate handshake and its absence does not abort the TLS negotiation in this default configuration. The failure would still occur even if OCSP were configured, because the server has no trust anchor to chain the client certificate to. This does not explain the observed handshake error.

  • ✗

    The client certificates were generated with ECDSA keys while the server is configured to accept only RSA client keys.

    Why it's wrong here

    Apache does not reject client certificates solely because of the key algorithm; it accepts any key type that forms a valid chain to the configured CA. A mismatch between ECDSA client keys and an RSA server key is normal and supported in TLS. This is not a plausible cause of a blanket handshake failure across all clients.

  • ✓

    The `SSLCACertificateFile` directive pointing to the internal CA trust anchor is missing or incorrect.

    Why this is correct

    With SSLVerifyClient require, the server must validate the client's chain against a configured trust anchor; without a correct SSLCACertificateFile (or SSLCACertificatePath) the handshake aborts because the presented certificate cannot be chained to a trusted root. Pointing this directive at the internal CA resolves the failure, which makes it the most likely cause here.

  • ✗

    The `SSLProtocol` directive allows only TLSv1.3, which does not support client certificate authentication.

    Why it's wrong here

    TLS 1.3 fully supports client certificate authentication, including post-handshake authentication in some implementations. Disabling earlier protocol versions does not disable client certificates. The claim that TLS 1.3 lacks this capability is technically false, so this cannot be the reason every connection now fails with a handshake error.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.