CompTIA Linux+ XK0-006 (V8) Practice Question

A junior Linux administrator is configuring a new public-facing web server and suggests using a self-signed SSL/TLS certificate to enable HTTPS, arguing it is free and provides encryption. As the senior administrator, what is the primary security risk you should explain to them regarding this approach?

  • The certificate cannot be automatically renewed, requiring manual intervention and increasing the risk of expiration.

  • The certificate is not signed by a trusted Certificate Authority (CA), which prevents clients from verifying the server's identity and makes man-in-the-middle (MITM) attacks much easier.

  • Self-signed certificates inherently use weaker cryptographic algorithms than those issued by a commercial CA.

  • Modern web servers like Nginx and Apache do not support the use of self-signed certificates for enabling HTTPS.

CompTIA Linux+ XK0-006 (V8)
Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot