Courseiva
Command and Control →mediumMultiple Choice

GPEN Command and Control Practice Question

Exhibit

Error Log: [2023-10-12 14:02:11] SSL_connect failed: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca

Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?

⚠ Common exam trap

Candidates often assume this error means the server is down or the network is blocked. They miss that the error is specifically a certificate validation failure by the client system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The client system does not trust the C2 server's certificate.

The 'tlsv1 alert unknown ca' error indicates that the client rejected the server's certificate because it was not signed by a trusted root CA. In the context of C2, this often happens when an automated beacon tries to connect to an infrastructure node using a self-signed certificate, and the host's security policy or a proxy is performing SSL inspection and fails the trust validation process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The C2 server is unreachable due to a network outage.

    Why it's wrong here

    A network outage would typically result in a connection timeout, 'connection refused', or 'no route to host' error. This specific error message indicates that the TCP connection was established and the SSL handshake process actually began, but failed during the authentication phase of the TLS negotiation.

  • ✓

    The client system does not trust the C2 server's certificate.

    Why this is correct

    This specific TLS alert signifies that the client received a certificate it could not verify against its local root store. This is a common indicator that the C2 infrastructure is using a self-signed certificate, which the client is configured to reject due to strict security settings.

  • ✗

    The C2 server is performing a man-in-the-middle attack.

    Why it's wrong here

    While this error could occur in a man-in-the-middle scenario, the error code implies that the client is the one rejecting the certificate. If the C2 server were the one attacking, it would likely be the client's own certificate that fails or a mismatch in the expected cipher suites.

  • ✗

    The C2 server has exhausted its connection limit.

    Why it's wrong here

    Connection limits are typically enforced at the network or application layer, resulting in '503 Service Unavailable' or TCP resets. A TLS-specific alert regarding an 'unknown CA' is strictly related to the cryptographic handshake and identity verification process, not the server's available resource capacity or connection load.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.