Courseiva

TLS Certificate Trust for Security+

A company launches a new HTTPS portal. Users should be able to confirm the site is really the company's portal and not a fake copy. Which control provides that trust?

Quick Answer

The answer is a TLS certificate issued by a trusted certificate authority. This control provides trust because browsers and operating systems maintain a root store of trusted CAs; when a user visits the HTTPS portal, the server presents a certificate signed by that CA, and the browser cryptographically verifies the signature chain back to a trusted root, ensuring the public key belongs to the claimed domain. On the Security+ SY0-701 exam, this tests your understanding of TLS certificate trust and authentication, often appearing in questions about preventing man-in-the-middle attacks or phishing portals. A common trap is confusing self-signed certificates with CA-issued ones—self-signed certificates lack a trusted root, so browsers display a warning. Remember the mnemonic: “Trust the Chain, Block the Fake”—if the certificate chain doesn’t end at a trusted root, the site is not authenticated.

⚠ Common exam trap

It's easy for candidates to confuse integrity checks (like SHA-256 checksums) with authentication mechanisms, or they think a self-signed certificate can be trusted if installed locally, but in practice, self-signed certificates lack the third-party validation needed to prevent man-in-the-middle attacks on a public-facing portal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A TLS certificate issued by a trusted certificate authority

A TLS certificate issued by a trusted certificate authority (CA) provides the trust needed because browsers and operating systems maintain a root store of trusted CAs. When a user visits the HTTPS portal, the server presents a certificate signed by that CA, and the browser cryptographically verifies the signature chain back to a trusted root. This ensures the public key belongs to the claimed domain, authenticating the server and preventing impersonation by a fake copy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A self-signed certificate installed only on user laptops

    Why it's wrong here

    A self-signed certificate is trusted only on machines where it was manually installed, so other users still cannot verify the portal's identity. It tempts for internal testing, but public trust requires a certificate from a publicly trusted certificate authority chaining to a root the browser already trusts.

  • ✓

    A TLS certificate issued by a trusted certificate authority

    Why this is correct

    A TLS certificate from a trusted certificate authority binds the portal's public key to its hostname, letting browsers verify authenticity and detect impostor copies. This satisfies the requirement that users confirm the site genuinely belongs to the company.

  • ✗

    A SHA-256 checksum posted on the login page

    Why it's wrong here

    A checksum verifies file integrity, not server identity, and a fake portal can publish its own matching hash. It tempts because hashes are used to validate downloads, but confirming the site is genuinely the company's requires a certificate issued by a trusted certificate authority.

  • ✗

    A shared password embedded in the page source

    Why it's wrong here

    A shared password in page source is readable by anyone who views the HTML, so it cannot prove the site's identity — it authenticates the visitor, not the server. Passwords suit access control, not server authentication. Confirming a portal is genuine requires a TLS certificate issued to the company and validated by the browser.

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, what is the best conclusion about the signed document?

hard
  • A.The invoice is confidential because the signature encrypts the document contents.
  • ✓ B.The invoice was not changed after signing and the signer’s certificate chain validated correctly.
  • C.The invoice can be edited if the timestamp is still within business hours.
  • D.The sender’s private key is now public because the certificate verified successfully.

Why B: A valid digital signature provides both integrity (the document was not altered after signing) and authentication (the signer's certificate chain validates to a trusted root). The exhibit shows a successful signature validation, which cryptographically proves that the invoice has not been modified since signing and that the signing certificate is trusted.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.