Courseiva
Web Communication Security →mediumMultiple Choice

GSEC Web Communication Security Practice Question

An administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?

⚠ Common exam trap

Candidates often blame expired server certificates or incorrect cipher suites rather than recognizing missing trust stores for internal CAs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The internal Root CA certificate is not installed in the client's local trust store.

Certificate warnings occur when a client cannot establish a chain of trust back to a trusted Root CA. In internal environments, the internal CA certificate must be explicitly imported into the client's trusted root store. Without this root trust, the browser cannot verify the digital signature of the server's certificate, resulting in a trust error. This is a fundamental concept in PKI management for enterprise web security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server certificate has expired, triggering a validity date error in the browser.

    Why it's wrong here

    Expiration errors specifically indicate that the current date is outside the Not Before and Not After range of the certificate. This is distinct from a chain of trust issue, which is caused by missing root certificates rather than the timing of the certificate lifecycle management process.

  • ✗

    The web server failed to send the intermediate certificate in the handshake process.

    Why it's wrong here

    While missing intermediates cause chain issues, the primary issue with internal CAs usually stems from the client not trusting the root itself. If the root CA is not in the local trust store, the chain cannot be completed, regardless of intermediate certificate inclusion in the handshake.

  • ✓

    The internal Root CA certificate is not installed in the client's local trust store.

    Why this is correct

    Web browsers rely on the local certificate store to validate the identity of web servers. If the issuing CA's root certificate is not present in the user's trusted root certification authorities store, the browser will signal that the site's identity cannot be verified, resulting in a security warning.

  • ✗

    The web application is utilizing an outdated TLS version that browsers no longer support.

    Why it's wrong here

    TLS version incompatibility results in a connection failure or a protocol error, not a certificate chain warning. Browser warnings specifically related to certificates denote an issue with the identity verification process, whereas protocol errors relate to the secure channel negotiation between the client and the server.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.