A Linux administrator is launching a new e-commerce website that will process sensitive customer financial data. The highest priorities are to establish maximum customer trust and ensure universal browser compatibility without security warnings. Which type of certificate should the administrator implement to best meet these requirements?
A self-signed certificate generated using OpenSSL.
A commercial certificate from a trusted Certificate Authority (CA).
A certificate signed by the company's internal CA.
A no-cost certificate from an automated CA (e.g., Let's Encrypt).
The correct choice is a commercial certificate from a trusted Certificate Authority (CA). For a public-facing e-commerce site handling financial data, establishing trust is paramount. Commercial CAs offer different levels of validation, including Organization Validated (OV) and Extended Validation (EV) certificates. These require a thorough vetting of the organization, providing a higher level of assurance to visitors compared to domain-only validation. Commercial certificates are universally trusted by all browsers, preventing security warnings that would deter customers. They also often come with financial warranties, which adds another layer of security assurance for the business.
A self-signed certificate is unsuitable because it is not signed by a trusted CA, which causes browsers to display prominent security warnings, eroding customer trust. A no-cost certificate, while valid and trusted by browsers for encryption, typically only offers Domain Validation (DV). This doesn't provide the organizational vetting that is crucial for a high-trust e-commerce platform. A certificate from an internal corporate CA is only intended for internal use and would not be trusted by the public or their browsers, resulting in security errors for external visitors.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is a commercial certificate from a trusted Certificate Authority (CA) universally trusted by browsers?
Open an interactive chat with Bash
What is the difference between Organization Validation (OV), Extended Validation (EV), and Domain Validation (DV) certificates?
Open an interactive chat with Bash
Why are self-signed certificates or internal CA certificates unsuitable for public-facing e-commerce websites?
Open an interactive chat with Bash
CompTIA Linux+ XK0-006 (V8)
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access