Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

A security team wants to implement a certificate pinning strategy for their mobile application to prevent man-in-the-middle attacks. Which of the following should be pinned in the application code?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server's public key

Certificate pinning involves pinning the public key of the server's certificate or the certificate itself. Pinning the public key allows for certificate renewal without updating the app.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The server's public key

    Why this is correct

    Pinning the server's public key, rather than the whole certificate, survives certificate renewal because the key pair persists across reissues. This satisfies the mobile app's requirement to block man-in-the-middle attacks without breaking connectivity each time the certificate rotates.

  • ✗

    The intermediate CA certificate

    Why it's wrong here

    Pinning the intermediate CA certificate fails because that CA can issue certificates for arbitrary hostnames, so a mis-issued certificate still validates against the pin. It is tempting for rotation convenience, but pinning the leaf's public key or SPKI hash restricts trust to the intended server.

  • ✗

    The server's IP address

    Why it's wrong here

    Pinning an IP address fails because TLS certificates bind to hostnames, not addresses, and IPs change with load balancers or CDN rotation, breaking connectivity. It is tempting as a crude allow-list, but pinning belongs to the certificate's public key or hash, not the network endpoint.

  • ✗

    The root CA certificate

    Why it's wrong here

    Pinning the root CA certificate fails because any certificate that CA issues for any domain would validate, so a mis-issued or compromised intermediate defeats the pin. It is tempting because roots are long-lived, but pinning the leaf public key or SPKI hash is what restricts trust to the specific server.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.