CompTIA Security+ (SY0-701)General Security ConceptsHard

A browser needs to verify in real time whether a website's certificate has been revoked, without downloading a large revocation list. Which protocol is used for this purpose?

  1. ACRL
  2. BLDAP
  3. CSCEP
  4. DOCSP
Show answer & explanation

Correct answer: D. OCSP

The Online Certificate Status Protocol (OCSP) allows a client to query a certificate authority in real time for the revocation status of a single certificate, avoiding the need to download an entire certificate revocation list (CRL).

Why the other options are wrong

  • A. CRL requires downloading a full list of revoked certificates, which the scenario says to avoid.
  • B. LDAP is a directory access protocol unrelated to certificate revocation checking.
  • C. SCEP is used for certificate enrollment, not revocation status checking.

OCSP

Online Certificate Status Protocol; allows real-time verification of an individual certificate's revocation status from a CA.

  • Faster and lighter than downloading a full CRL
  • OCSP stapling lets the web server provide the response, improving privacy and performance
  • Response is signed by the CA or an authorized responder

Memory trick: OCSP = On-demand Check, Single Piece

More General Security Concepts questions