GPEN Command and Control Practice Question
Exhibit
Error Log: [2023-10-12 14:02:11] SSL_connect failed: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca
Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?
⚠ Common exam trap
Candidates often assume this error means the server is down or the network is blocked. They miss that the error is specifically a certificate validation failure by the client system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The client system does not trust the C2 server's certificate.
The 'tlsv1 alert unknown ca' error indicates that the client rejected the server's certificate because it was not signed by a trusted root CA. In the context of C2, this often happens when an automated beacon tries to connect to an infrastructure node using a self-signed certificate, and the host's security policy or a proxy is performing SSL inspection and fails the trust validation process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The C2 server is unreachable due to a network outage.
Why it's wrong here
A network outage would typically result in a connection timeout, 'connection refused', or 'no route to host' error. This specific error message indicates that the TCP connection was established and the SSL handshake process actually began, but failed during the authentication phase of the TLS negotiation.
- ✓
The client system does not trust the C2 server's certificate.
Why this is correct
This specific TLS alert signifies that the client received a certificate it could not verify against its local root store. This is a common indicator that the C2 infrastructure is using a self-signed certificate, which the client is configured to reject due to strict security settings.
- ✗
The C2 server is performing a man-in-the-middle attack.
Why it's wrong here
While this error could occur in a man-in-the-middle scenario, the error code implies that the client is the one rejecting the certificate. If the C2 server were the one attacking, it would likely be the client's own certificate that fails or a mismatch in the expected cipher suites.
- ✗
The C2 server has exhausted its connection limit.
Why it's wrong here
Connection limits are typically enforced at the network or application layer, resulting in '503 Service Unavailable' or TCP resets. A TLS-specific alert regarding an 'unknown CA' is strictly related to the cryptographic handshake and identity verification process, not the server's available resource capacity or connection load.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.