Skip to content
CA-003
Secure agent communication
hard
Question 4 of 24

A security team is hardening a Consul datacenter and must ensure that no client certificate can be used to impersonate a server. Beyond setting verify_server_hostname = true, which additional TLS configuration must be set so that clients verify the server certificate against the cluster CA?

Aca_file must point to the CA certificate and verify_outgoing = true
BOnly encrypt needs to be set for full TLS security
Cauto_encrypt.allow_tls = true is sufficient on its own
Dverify_incoming = true must be set on all client agents

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion