ExamGecko
Question list
Search
Search

Related questions











Question 77 - HPE7-A01 discussion

Report
Export

What is one advantage of using OCSP vs CRLs for certificate validation?

A.
reduces latency between the time a certificate is revoked and validation reflects this status
Answers
A.
reduces latency between the time a certificate is revoked and validation reflects this status
B.
less complex to implement
Answers
B.
less complex to implement
C.
higher availability for certificate validation
Answers
C.
higher availability for certificate validation
D.
supports longer certificate validity periods
Answers
D.
supports longer certificate validity periods
Suggested answer: A

Explanation:

OCSP is a protocol that allows clients to query the CA or a trusted responder for the status of a specific certificate.OCSP requests and responses are smaller and faster than CRLs, and they can provide real-time information about the revocation status of a certificate12. CRLs are lists of all revoked certificates that are downloaded from the CA.CRLs can present issues, as they can become outdated and have to be downloaded frequently13.Therefore, OCSP reduces latency between the time a certificate is revoked and validation reflects this status.

Reference:1https://sectigostore.com/blog/ocsp-vs-crl-whats-the-difference/2https://www.keyfactor.com/blog/what-is-a-certificate-revocation-list-crl-vs-ocsp/3https://www.fortinet.com/resources/cyberglossary/ocsp

asked 16/09/2024
Ilia Voronkov
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first