Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HPE6-A78 Exam - Topic 2 Question 95 Discussion

Device A is contacting https://arubapedia.arubanetworks.com. The web server sends a certificate chain. What does the browser do as part of validating the web server certificate?
B) It makes sure the certificate has a DNS SAN that matches arubapedia.arubanetworks.com
A) It makes sure that the key in the certificate matches the key that DeviceA uses for HTTPS.
C) It makes sure that the public key in the certificate matches DeviceA's private HTTPS key.
D) It makes sure that the public key in the certificate matches a private key stored on DeviceA.

HPE6-A78 Exam - Topic 2 Question 95 Discussion

Actual exam question for HP's HPE6-A78 exam
Question #: 95
Topic #: 2
[All HPE6-A78 Questions]

Device A is contacting https://arubapedia.arubanetworks.com. The web server sends a certificate chain. What does the browser do as part of validating the web server certificate?

Show Suggested Answer Hide Answer
Suggested Answer: B

When a device like Device A contacts a secure website and receives a certificate chain from the server, the browser's primary task is to validate the web server's certificate to ensure it is trustworthy. Part of this validation includes checking that the certificate contains a DNS Subject Alternative Name (SAN) that matches the domain name of the website being accessed---in this case, arubapedia.arubanetworks.com. This ensures that the certificate was indeed issued to the entity operating the domain and helps prevent man-in-the-middle attacks where an invalid certificate could be presented by an attacker. The DNS SAN check is critical because it directly ties the digital certificate to the domain it secures, confirming the authenticity of the website to the user's browser.


Contribute your Thoughts:

0/2000 characters
Hubert
10 hours ago
Exactly! A and B are more relevant here.
upvoted 0 times
...
Phyliss
6 days ago
C is confusing. Public and private keys are different.
upvoted 0 times
...
Shanice
11 days ago
D sounds plausible, but it’s not the main focus.
upvoted 0 times
...
Kimbery
16 days ago
A makes sense too, but B feels more specific.
upvoted 0 times
...
Hubert
21 days ago
I prefer A. Key matching is crucial.
upvoted 0 times
...
Eileen
26 days ago
The DNS SAN must match the domain.
upvoted 0 times
...
Phyliss
1 month ago
Why B?
upvoted 0 times
...
Eileen
1 month ago
I think B is the right answer.
upvoted 0 times
...
Kimbery
1 month ago
This question is tricky.
upvoted 0 times
...
Man
2 months ago
I thought it was all about the public key matching!
upvoted 0 times
...
Serita
2 months ago
Wait, does the browser really check the private key? Sounds off.
upvoted 0 times
...
Tony
2 months ago
A and C are confusing, they don't really apply here.
upvoted 0 times
...
Tresa
2 months ago
Definitely B! The DNS SAN has to match.
upvoted 0 times
...
Heike
2 months ago
The browser checks the certificate chain for validity.
upvoted 0 times
...
Kattie
2 months ago
I thought the browser validates the certificate chain first, but I can't remember if it checks the SAN or the keys first.
upvoted 0 times
...
Krystina
3 months ago
I feel like option A is related to how the keys work, but I don't remember if it's specifically about matching Device A's key.
upvoted 0 times
...
Rosendo
3 months ago
I remember practicing a question like this where the public key had to match the private key, but I can't recall the exact details.
upvoted 0 times
...
Pearly
3 months ago
I think the browser checks if the certificate has a DNS SAN that matches the website, but I'm not entirely sure if that's the main step.
upvoted 0 times
...

Save Cancel