CompTIA Security+ (SY0-701)General Security ConceptsHard
A browser displays a certificate error stating that it cannot build a valid path from a website's certificate up to a trusted root certificate authority. Which PKI concept explains why this validation failed?
- AThe certificate uses a weak hashing algorithm
- BThe chain of trust is broken
- CThe certificate revocation list was not updated
- DKey escrow was not configured for the root CA
Show answer & explanationAnswer & explanation
Correct answer: B. The chain of trust is broken
PKI relies on a chain of trust where each certificate is validated up to a trusted root CA; if an intermediate certificate is missing or invalid, the browser cannot establish this chain, causing a validation failure.
Why the other options are wrong
- A. A weak hashing algorithm might trigger a different warning about signature algorithm security, not a path-building error.
- C. An outdated CRL would cause a revocation-related warning, not a path-building failure.
- D. Key escrow relates to private key recovery and is unrelated to certificate path validation.
Chain of Trust
The hierarchical validation path from an end-entity certificate through intermediate CAs up to a trusted root CA that establishes certificate legitimacy.
- Root CA certificates are self-signed and trusted by default
- Intermediate CAs bridge trust between root and end-entity certs
- A missing or misconfigured intermediate cert breaks the chain
Memory trick: No unbroken links, no trust to the top.