SY0-701 · Question #160
SY0-701 Question #160: Real Exam Question with Answer & Explanation
The correct answer is D: CRL. From a practical standpoint, an administrator would use automation to compare all existing certificates with the revocation list, but potentially they could also script to OCSP per each certificate in the environment. Either option seem valid, but CRL seems the better option from
Question
A certificate vendor notified a company that recently invalidated certificates may need to be updated. Which of the following mechanisms should a security administrator use to determine whether the certificates installed on the company's machines need to be updated?
Options
- ASCEP
- BOCSP
- CCSR
- DCRL
Explanation
From a practical standpoint, an administrator would use automation to compare all existing certificates with the revocation list, but potentially they could also script to OCSP per each certificate in the environment. Either option seem valid, but CRL seems the better option from enterprise scan perspective.
Community Discussion
No community discussion yet for this question.