nerdexam
CompTIA

SY0-301 · Question #866

Which of the following digital certificate management practices will ensure that a lost certificate is not compromised?

The correct answer is D. CRL. A CRL (Certificate Revocation List) is a list published by a Certificate Authority (CA) that contains certificates that have been revoked before their expiration date. If a certificate is lost, it should be revoked and added to the CRL so that relying parties know not to trust…

General security concepts

Question

Which of the following digital certificate management practices will ensure that a lost certificate is not compromised?

Options

  • AKey escrow
  • BNon-repudiation
  • CRecovery agent
  • DCRL

How the community answered

(31 responses)
  • B
    6% (2)
  • C
    3% (1)
  • D
    90% (28)

Explanation

A CRL (Certificate Revocation List) is a list published by a Certificate Authority (CA) that contains certificates that have been revoked before their expiration date. If a certificate is lost, it should be revoked and added to the CRL so that relying parties know not to trust it - preventing it from being used maliciously if found. Key escrow stores copies of private keys with a trusted third party (for recovery, not revocation). Non-repudiation ensures actions can be attributed to a party and cannot be denied. A recovery agent is used to decrypt data when a user's key is lost, not to prevent a compromised certificate from being used.

Topics

#CRL#PKI#certificate revocation#certificate management

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice