Courseiva
Application And Data ProtectionmediumMultiple ChoiceObjective-mapped

CND Application And Data Protection Practice Question

A security administrator is configuring a corporate proxy server (Squid) to inspect outbound HTTPS traffic from endpoints. To perform SSL interception (Man-in-the-Middle inspection) for content filtering and DLP, what cryptographic setup must be installed on client workstations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The proxy's custom Root CA certificate installed into the workstations' Trusted Root Certification Authorities store

For a forward proxy to decrypt and inspect HTTPS traffic, the proxy's internal Certificate Authority (CA) root certificate must be installed into the trusted root certification authorities certificate store of each client workstation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The proxy's custom Root CA certificate installed into the workstations' Trusted Root Certification Authorities store

    Why this is correct

    Clients must trust the proxy's signing CA certificate to accept the re-signed TLS certificates without browser warnings.

  • The public keys of every external website visited by users

    Why it's wrong here

    Client workstations already trust public CAs; installing individual website keys is unfeasible.

  • An expired SSLv2 certificate bundle

    Why it's wrong here

    Expired SSLv2 certificates are insecure and rejected by modern operating systems.

  • Self-signed SSH host keys generated on the Squid proxy

    Why it's wrong here

    SSH keys are used for remote terminal administration, not HTTPS web proxy certificate trust.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CND question is part of Courseiva's 323-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.