A vulnerability scanner reports that an internal web service is using an expired TLS certificate. Which classification best describes the finding?
Select an answer to reveal the explanation.
Short Explanation
Think of an expired TLS certificate like a driver's license that's gone stale — the car still runs, but you can't prove it's current. You shouldn't patch the engine when the paperwork is bad. The real issue is certificate lifecycle management, not a software flaw.
Full Explanation
An expired TLS certificate is a cryptographic control failure because the service is presenting a credential whose validity period has elapsed, which breaks trust establishment and may expose users to man-in-the-middle or authentication-warning risk. The scanner is not identifying vulnerable code; it is evaluating certificate attributes such as expiration date, issuer, and chain validity. A software vulnerability classification would be incorrect because patching the web server package does not renew the certificate or restore a valid trust chain. A network misclassification would also be wrong because firewall rules do not alter certificate validity, although they may affect reachability. An access control finding is similarly wrong because permissions govern who may connect or administer the service, not whether the presented certificate is cryptographically valid. Exam caveat: CS0-004 expects you to separate vulnerability findings by failure type, not just by scanner severity. Operational check: confirm the certificate expiration date, renewal owner, and replacement plan in the certificate inventory before closing the ticket.