hardMultiple Choice
CISSP Practice Question: That a VPN client cannot connect to the corporate…
Exhibit
ERROR: Certificate verification failed: unable to get local issuer certificate
A user reports that a VPN client cannot connect to the corporate gateway. The client log shows the following excerpt: "TLS Error: server certificate verification failed: unable to get local issuer certificate." What does this indicate?
⚠ Common exam trap
Candidates often confuse 'certificate expired' with 'untrusted CA' — both cause failures, but the log message and the underlying PKI process are different, and ISC2 often tests the distinction between trust chain errors and expiration errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The client does not trust the CA that issued the server certificate
The log message 'unable to get local issuer certificate' indicates that the client cannot locate or trust the CA certificate that issued the VPN server certificate. This is a trust chain issue, not an expired server certificate, a self-signed certificate, or a missing client certificate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPN server certificate is expired
Why it's wrong here
An expired VPN server certificate would result in a specific error message indicating that the certificate's validity period has passed. The client's VPN software would explicitly report a 'certificate expired' or 'validity period not current' error, which is distinct from a general trust failure where the certificate itself might be valid but its issuer is unknown or untrusted. This specific error helps pinpoint the exact lifecycle issue with the certificate.
- ✗
The server is using a self-signed certificate
Why it's wrong here
When a server uses a self-signed certificate, the client cannot establish a trust chain back to a recognized Certificate Authority (CA) because the certificate is its own root. This typically leads to an 'untrusted root certificate' or 'certificate chain incomplete' error, often prompting the user to manually accept the certificate as an exception. This is different from a scenario where a CA exists but is simply not present in the client's trusted store.
- ✗
The client certificate is missing
Why it's wrong here
If the VPN client certificate is missing, it implies that the server requires client-side authentication, and the client failed to provide its credentials. The server would reject the connection with an 'authentication failed' or 'client certificate required' error, as it cannot verify the client's identity. This is a client authentication issue, not a problem with the client's ability to trust the server's identity or its certificate.
- ✓
The client does not trust the CA that issued the server certificate
Why this is correct
This is the correct answer because the client receives the server's certificate but cannot validate its authenticity. The client attempts to trace the certificate's issuer back to a trusted root Certificate Authority (CA) in its local trust store. If the issuing CA's certificate, or any intermediate CA in the chain, is not found or recognized as trusted by the client, the validation process fails, preventing the secure connection from being established due to an untrusted certificate chain.
Go deeper
Related to this question
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
TLS
Transport Layer Security (TLS) is a cryptographic protocol that encrypts data sent over the internet to keep it private and ensure it hasn’t been tampered with.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.