CompTIA Security+ (SY0-701)Security OperationsHard
A web application uses TLS certificates issued by a public certificate authority. After a private key compromise is discovered, the security team immediately notifies the CA, which adds the certificate's serial number to a published list that browsers can check to reject the compromised certificate before its scheduled expiration. Which mechanism does this describe?
- ACertificate transparency logging
- BCertificate pinning
- CCertificate signing request (CSR) renewal
- DCertificate revocation via CRL/OCSP
Show answer & explanationAnswer & explanation
Correct answer: D. Certificate revocation via CRL/OCSP
Certificate revocation allows a CA to invalidate a certificate before its natural expiration by publishing it on a Certificate Revocation List (CRL) or making it queryable via the Online Certificate Status Protocol (OCSP), so clients can reject compromised certificates.
Why the other options are wrong
- A. Certificate transparency is a public log of issued certificates for auditing issuance, not revocation status.
- B. Certificate pinning hardcodes an expected certificate/key in an application, unrelated to CA-issued revocation lists.
- C. CSR renewal is the process of requesting a new certificate, not invalidating a compromised one.
Certificate Revocation (CRL/OCSP)
A mechanism allowing a certificate authority to invalidate a certificate before its expiration date, published via a Certificate Revocation List (CRL) or checked in real time via OCSP.
- CRL: periodically published list of revoked certificate serial numbers
- OCSP: real-time query protocol to check a single certificate's status
- Used when a private key is compromised or certificate details change
Memory trick: A revoked certificate gets blacklisted before its natural death (expiration).