220-1102 exam dumps

220-1102 practice question 478 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 478

Single answerExpiration

A technician is troubleshooting why several users can no longer connect to the company VPN from their laptops. The VPN client reports that the server certificate is not valid, and the issue began suddenly this morning for all affected users. Internal network connectivity is working, and no recent VPN client updates were installed. Which of the following is the MOST likely cause?

  1. A

    The VPN server's SSL/TLS certificate has expired

  2. B

    The users' passwords have reached the maximum password age

  3. C

    The DHCP lease for the laptops has expired

  4. D

    The VPN server's IP address has changed because of DNS propagation

Show answer and explanation

Correct answer: A

Explanation

This question tests applied knowledge of expiration-related issues in a security and remote access context. In A+ Core 2, candidates are expected to recognize practical causes of authentication and connectivity failures, including certificate expiration. When a service that uses SSL/TLS suddenly fails for many users and the error specifically references certificate validity, an expired certificate is the most likely cause. By contrast, password expiration affects individual user authentication, DHCP lease expiration affects local addressing, and DNS/IP changes usually lead to name resolution or connectivity symptoms rather than certificate validity warnings. This aligns with standard PKI and certificate lifecycle best practices documented by major vendors such as Microsoft and common VPN platform guidance, which emphasize monitoring and renewing certificates before their Not After expiration date.

  • A. Correct.

    Correct. A VPN client warning that the server certificate is not valid, especially when it begins affecting multiple users at the same time, strongly indicates that the VPN server's SSL/TLS certificate has expired. Certificate expiration is time-based, so widespread failures often start abruptly on the expiration date. This is a common real-world issue with remote access services that rely on certificate validation.

  • B. Incorrect.

    Incorrect. Expired user passwords can prevent authentication, but they do not typically generate an error stating that the server certificate is not valid. Password expiration affects user login credentials, not the trust status of the VPN server identity certificate.

  • C. Incorrect.

    Incorrect. An expired DHCP lease could affect IP addressing and network connectivity, but the scenario states that internal network connectivity is working. Also, DHCP lease expiration would not specifically cause a certificate validity warning from the VPN client.

  • D. Incorrect.

    Incorrect. A DNS or IP address change could cause connection failures if clients cannot reach the correct server, but it would not normally trigger a message that the server certificate is not valid unless there were a name mismatch or trust issue. The sudden, broad timing points more directly to certificate expiration.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam