Courseiva
easyMultiple Choice

CAS-004 Practice Question: An engineer reviews the TLS configuration for a…

Exhibit

Refer to the exhibit.

Exhibit:
```
ssl_cert_path = /etc/ssl/certs/server.pem
ssl_key_path = /etc/ssl/private/server.key
ssl_protocols = TLSv1.2 TLSv1.3
ssl_ciphers = ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256
ssl_verify_client = optional
```

An engineer reviews the TLS configuration for a web server, which includes the following line: ssl_verify_client optional; Which of the following is a security concern present in this configuration?

⚠ Common exam trap

CAS-005 often tests the security implication of 'optional' vs 'on' for client certificate verification — candidates may overlook that 'optional' does not enforce authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server does not require client certificates for authentication.

The directive ssl_verify_client optional; means the server will request a client certificate but will not require it; if the client does not present one, the connection still proceeds. This weakens mutual TLS authentication because clients are not forced to authenticate with certificates, allowing unauthenticated access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cipher suite does not include perfect forward secrecy (PFS).

    Why it's wrong here

    Cipher suite selection is configured through ssl_ciphers, a separate directive; ssl_verify_client governs client certificate checking and says nothing about forward secrecy. It is tempting because absent perfect forward secrecy is a real TLS weakness, and it would be the concern if the cipher list omitted ECDHE or DHE key exchange suites.

  • ✗

    The configuration supports outdated TLS 1.2 protocols.

    Why it's wrong here

    TLS version support is set by ssl_protocols, not ssl_verify_client; the directive only controls whether client certificates are requested. It is tempting because deprecated protocol versions are a genuine TLS weakness, and it would be the concern if ssl_protocols still enabled TLS 1.0 or 1.1.

  • ✗

    The private key is stored in an accessible location.

    Why it's wrong here

    The directive concerns client certificate verification, not key storage; key file permissions are governed separately and are unaffected by ssl_verify_client. It is tempting because exposed private keys are a genuine critical TLS weakness, and that would be the answer if the configuration or file permissions actually showed the key readable by untrusted users.

  • ✓

    The server does not require client certificates for authentication.

    Why this is correct

    With ssl_verify_client optional, nginx requests a certificate but accepts connections lacking one, so the client certificate is never enforced as an authentication factor. Any client can complete the handshake without proving identity, satisfying the stem's concern that certificates are not required.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.