Recommended Posts

I'm studying for the Security+ certification and don't really understand an answer to the question (see below). I've tried searching online and can't seem to find a clear answer on what a certificate CN is and what an A record is...can somebody please explain?...

Which of the following is true when Sara, a user, browsing to an HTTPS site receives the

message: 'Site name mismatch'?

A. The certificate CN is different from the site DNS A record.

B. The CA DNS name is different from the root certificate CN.

C. The certificate was issued by the intermediate CA and not by the root CA.

D. The certificate file name is different from the certificate CN.

Answer: A

Link to comment
https://www.neowin.net/forum/topic/1145294-understanding-security-question/
Share on other sites

I'm taking my Security+ course in college right now so maybe I can help.

What answer A is basically telling you is that the Certificate Name (the web site name the certificate was issued to) does not match the host record (the web site name that Sara is visiting) on the DNS server.

Example: Sara types https://www.bobs-web-site.org into her browser and when she gets there her browser finds an SSL certificate issued to stans-web-site.net.

Does this help?

I don't like the wording of the answer --- the dns record might not even come into play, What if the user is using a host file? Or what if user is accessing site via netbios name on a local lan?

Better wording might of been CN does not match url used to access site. Maybe the user accessed site via http:\\ipaddress

A dns A record is an IP for a host name in a specific zone - so again wording is not correct for what they are wanting you to understand.

What if going to www.domainx.com which is a cname that points to www.domainb.com, etc. No A record for the FQDN (fully qualified domain name) the user used to access the site. There would be an A record for www.domainb.com, but no A record for where you went.

CN stands for common name, which is a field on the cert when generated.

if you get a mismatch error, all its telling you use the URL in your browser does not match the common name on the cert. Saying it does not match the A record is not really accurate since they don't even say how the user accessed the site. Could of been via IP or netbios name, etc.

Not sure what material your using - but seems from your multiple questions in the past, its not a very good resource.

This topic is now closed to further replies.
  • Posts

    • Rockstar confirms Grand Theft Auto VI pre-orders begin next week, unveils cover art by Pulasthi Ariyasinghe The release date of Grand Theft Auto VI has moved quite a lot since its original announcement in 2023, but it finally looks like the game has found its final launch slot. Rockstar today had a new video upload on its YouTube channel, and while it wasn't a new trailer for the game, the company revealed two things. This was the pre-order kickoff date for Grand Theft Auto VI as well as the game's official cover art. The company revealed that June 25 is when fans of the series will be able to pre-order their copy of Grand Theft Auto VI. Pre-orders will be available both digitally and in retail stores. The newly unveiled cover art shows off the two new protagonists, as well as a few more characters that are probably vital to the campaign storyline. Shots of vehicles players can use like a light helicopter, motorcycle, sports car, and speed boat are also seen here, alongside a shot of a crocodile. "Jason and Lucia have always known the deck is stacked against them," says Rockstar describing the campaign's protagonist duo. "But when an easy score goes wrong, they find themselves on the darkest side of the sunniest place in America, in the middle of a conspiracy stretching across the state of Leonida — forced to rely on each other more than ever if they want to make it out alive." Grand Theft Auto VI is coming to Xbox Series X|S and PlayStation 5 on November 19, 2026. A PC version has not been confirmed yet, though it's expected by many to land after the console release. When asked about this, the Take-Two CEO says it considers the core audience for the Grand Theft Auto franchise to be on consoles.
    • In rare occasions when you turn your computer on you will be greeted with a Secure Boot error followed by the message "No boot device found" If you go into the UEFI and disable Secure Boot the system boots up just fine. Below is a method I found online to fix the issue Disable Secure Boot and boot into Windows (If Bitlocker is enable you'll have to go to https://aka.ms/myrecoverykey on another device to find your bitlocker recovery key). Find a flash drive and make sure it's formatted Fat32 Create a folder on the flash drive called EFI and a subfolder inside EFI called BOOT On your computer navigate to C:\windows\boot\EFI Copy the file SecureBootRecovery.efi to your flash drive\EFI\BOOT Now reboot the computer and tell the computer to boot off that flash drive. You should see a black screen with some text telling you it has repaired Secure Boot Turn Secure Boot back on and reboot and your computer should boot normally.  
  • Recent Achievements

    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      552
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      72
    4. 4
      Michael Scrip
      64
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!