FC0-U71 Security Practice Question
A user's web browser warns that the connection to an online store is not private because the site's certificate cannot be validated. The user ignores the warning and enters payment card details anyway. Which type of attack is the user MOST at risk of in this situation?
⚠ Common exam trap
The trap here is treating a certificate warning as a harmless glitch, when it actually undermines the identity check that protects against an on-path attacker.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
On-path attack intercepting the unverified connection.
When a browser cannot validate a site's certificate, the identity of the server is in doubt, which is the hallmark of an on-path attack redirecting traffic to an imposter endpoint. Entering payment details in that state can hand them directly to the attacker. The other listed attacks target availability or server-side application flaws and are not signaled by a certificate validation warning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection against the store's product database.
Why it's wrong here
SQL injection targets a web application's database queries and is executed by an attacker against the server, not by a user typing into a payment form. A certificate warning concerns the identity of the endpoint, not malformed database input. The user's action does not trigger SQL injection, so this is unrelated to the scenario.
- ✗
Denial-of-service attack flooding the store's web server.
Why it's wrong here
A denial-of-service attack aims to make a service unavailable by exhausting its resources, not to capture the user's payment details. The warning about certificate validation does not indicate traffic flooding, and the user entering card data does not contribute to taking the store offline. This attack type does not match the confidentiality risk described.
- ✗
Cross-site scripting running in the store's checkout page.
Why it's wrong here
Cross-site scripting injects malicious scripts into pages viewed by other users and typically exploits poor input handling on the site. The browser warning here is about certificate validation, which points to an endpoint identity problem rather than injected script content. Ignoring the warning does not specifically expose the user to cross-site scripting.
- ✓
On-path attack intercepting the unverified connection.
Why this is correct
A certificate validation failure often means the browser cannot confirm it is talking to the real store, which is exactly the condition an on-path attacker creates by inserting themselves between the user and the site. Continuing past the warning can send card details through the attacker's system. Trusting an unvalidated certificate defeats the protection TLS is meant to provide.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.