CompTIA Security+ (SY0-701)Security OperationsHard

A web application uses TLS certificates issued by a public certificate authority. After a private key compromise is discovered, the security team immediately notifies the CA, which adds the certificate's serial number to a published list that browsers can check to reject the compromised certificate before its scheduled expiration. Which mechanism does this describe?

  1. ACertificate transparency logging
  2. BCertificate pinning
  3. CCertificate signing request (CSR) renewal
  4. DCertificate revocation via CRL/OCSP
Show answer & explanation

Correct answer: D. Certificate revocation via CRL/OCSP

Certificate revocation allows a CA to invalidate a certificate before its natural expiration by publishing it on a Certificate Revocation List (CRL) or making it queryable via the Online Certificate Status Protocol (OCSP), so clients can reject compromised certificates.

Why the other options are wrong

  • A. Certificate transparency is a public log of issued certificates for auditing issuance, not revocation status.
  • B. Certificate pinning hardcodes an expected certificate/key in an application, unrelated to CA-issued revocation lists.
  • C. CSR renewal is the process of requesting a new certificate, not invalidating a compromised one.

Certificate Revocation (CRL/OCSP)

A mechanism allowing a certificate authority to invalidate a certificate before its expiration date, published via a Certificate Revocation List (CRL) or checked in real time via OCSP.

  • CRL: periodically published list of revoked certificate serial numbers
  • OCSP: real-time query protocol to check a single certificate's status
  • Used when a private key is compromised or certificate details change

Memory trick: A revoked certificate gets blacklisted before its natural death (expiration).

More Security Operations questions