Which Certificate Type Best Secures Multiple Domains and Subdomains Cost-Effectively?
A security administrator is working to find a cost-effective solution to implement certificates for a large number of domains and subdomains owned by the company. Which of the following types of certificates should the administrator implement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of certificate scope versus cost efficiency, with the common trap being confusion between wildcard certificates and self-signed alternatives for production deployments.
This question explores the most cost-effective SSL/TLS certificate type for securing multiple subdomains under a single parent domain. The community overwhelmingly agrees that a wildcard certificate is the correct choice due to its ability to cover an entire domain hierarchy with a single issuance.
Many candidates incorrectly select Self-signed certificates, assuming that avoiding CA fees makes them more cost-effective for large-scale deployments. However, self-signed certificates lack public trust, generate constant browser warnings, and fail compliance requirements for production environments.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Wildcard Certificates
A wildcard certificate is specifically designed to secure a base domain and all of its immediate subdomains using a single certificate issuance (e.g.,*.company.com). As highlighted by community experts, purchasing one wildcard certificate eliminates the administrative overhead and recurring costs of managing individual certificates for every subdomain, making it the optimal cost-effective solution for organizations scaling their web infrastructure.Why the Other Options Fail
Client certificates are used for mutual TLS (mTLS) and device/user authentication, not for hosting multiple websites. Self-signed certificates (Option C) bypass Certificate Authorities entirely, which initially saves money but creates severe operational friction. As noted by candidates who initially debated this option, self-signed certs trigger persistent browser security warnings and break automated compliance checks, rendering them unsuitable for enterprise-scale deployments. Code signing certificates (Option D) are exclusively used to verify the integrity and publisher identity of software binaries, having no relation to domain validation or web traffic encryption.Exam Context
The phrasing "large number of domains and subdomains" is a classic CompTIA indicator pointing toward either a wildcard or Subject Alternative Name (SAN) certificate. Since SAN isn't listed, wildcard is the definitive answer. Always prioritize certificates that align with both the technical requirement (encryption/hosting) and the business constraint (cost/scale).Official Reference
Exam Strategy
When encountering certificate deployment scenarios, first identify the primary function required (web hosting, software distribution, or authentication) before weighing secondary constraints like budget. If a question emphasizes managing many subdomains efficiently, immediately filter out specialized certificates (code signing, client auth) and focus on domain-validation types, selecting wildcard or SAN based on available options.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →