CompTIA A+ Core 2 (220-1202)Software TroubleshootingHard
A user connects to a coffee shop's public Wi-Fi and attempts to log into their online banking site. The browser displays 'Your connection is not private' with a certificate warning, something the user has never seen on this site before. What should the user do?
- ASwitch to a different browser and log in as normal
- BDisconnect from the network immediately and avoid entering any credentials until on a trusted network
- CClear the browser cache and reload the page to dismiss the warning
- DClick 'Proceed anyway' since banking sites often have certificate issues on public networks
Show answer & explanationAnswer & explanation
Correct answer: B. Disconnect from the network immediately and avoid entering any credentials until on a trusted network
An unexpected certificate warning on a previously trusted site, especially over public Wi-Fi, is a strong indicator of a possible on-path (man-in-the-middle) attack intercepting traffic. The safest response is to disconnect and avoid entering credentials until connected to a trusted, verified network.
Why the other options are wrong
- A. Switching browsers doesn't fix a network-level interception issue.
- C. Clearing cache does not resolve a genuine certificate mismatch from network interception.
- D. Proceeding anyway risks submitting credentials to an attacker intercepting the connection.
On-Path (Man-in-the-Middle) Attack Indicator
An unexpected SSL/TLS certificate warning on a normally trusted site, especially on public Wi-Fi, can indicate traffic is being intercepted by an attacker positioned between the user and the destination server.
- Public Wi-Fi is a common attack vector
- Certificate warnings should never be dismissed on sensitive sites
- Best response is to disconnect and use a trusted network
Memory trick: 'Free Wi-Fi, costly trust' — a cert warning means someone's listening in.