Courseiva
hardMultiple Choice

CISSP Practice Question: That a VPN client cannot connect to the corporate…

Exhibit

ERROR: Certificate verification failed: unable to get local issuer certificate

A user reports that a VPN client cannot connect to the corporate gateway. The client log shows the following excerpt: "TLS Error: server certificate verification failed: unable to get local issuer certificate." What does this indicate?

⚠ Common exam trap

Candidates often confuse 'certificate expired' with 'untrusted CA' — both cause failures, but the log message and the underlying PKI process are different, and ISC2 often tests the distinction between trust chain errors and expiration errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The client does not trust the CA that issued the server certificate

The log message 'unable to get local issuer certificate' indicates that the client cannot locate or trust the CA certificate that issued the VPN server certificate. This is a trust chain issue, not an expired server certificate, a self-signed certificate, or a missing client certificate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPN server certificate is expired

    Why it's wrong here

    An expired VPN server certificate would result in a specific error message indicating that the certificate's validity period has passed. The client's VPN software would explicitly report a 'certificate expired' or 'validity period not current' error, which is distinct from a general trust failure where the certificate itself might be valid but its issuer is unknown or untrusted. This specific error helps pinpoint the exact lifecycle issue with the certificate.

  • ✗

    The server is using a self-signed certificate

    Why it's wrong here

    When a server uses a self-signed certificate, the client cannot establish a trust chain back to a recognized Certificate Authority (CA) because the certificate is its own root. This typically leads to an 'untrusted root certificate' or 'certificate chain incomplete' error, often prompting the user to manually accept the certificate as an exception. This is different from a scenario where a CA exists but is simply not present in the client's trusted store.

  • ✗

    The client certificate is missing

    Why it's wrong here

    If the VPN client certificate is missing, it implies that the server requires client-side authentication, and the client failed to provide its credentials. The server would reject the connection with an 'authentication failed' or 'client certificate required' error, as it cannot verify the client's identity. This is a client authentication issue, not a problem with the client's ability to trust the server's identity or its certificate.

  • ✓

    The client does not trust the CA that issued the server certificate

    Why this is correct

    This is the correct answer because the client receives the server's certificate but cannot validate its authenticity. The client attempts to trace the certificate's issuer back to a trusted root Certificate Authority (CA) in its local trust store. If the issuing CA's certificate, or any intermediate CA in the chain, is not found or recognized as trusted by the client, the validation process fails, preventing the secure connection from being established due to an untrusted certificate chain.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.