ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 284 - CAS-004 discussion

Report
Export

Some end users of an e-commerce website are reporting a delay when browsing pages. The website uses TLS 1.2. A security architect for the website troubleshoots by connecting from home to the

website and capturing tramc via Wire-shark. The security architect finds that the issue is the time required to validate the certificate. Which of the following solutions should the security architect

recommend?

A.
Adding more nodes to the web server clusters
Answers
A.
Adding more nodes to the web server clusters
B.
Changing the cipher algorithm used on the web server
Answers
B.
Changing the cipher algorithm used on the web server
C.
Implementing OCSP stapling on the server
Answers
C.
Implementing OCSP stapling on the server
D.
Upgrading to TLS 1.3
Answers
D.
Upgrading to TLS 1.3
Suggested answer: C

Explanation:

OCSP stapling is a solution that allows the web server to provide a time-stamped OCSP response signed by the CA along with the certificate during the TLS handshake, eliminating the need for the client to contact the CA separately to validate the certificate. OCSP stapling can reduce the delay caused by the certificate validation process by saving a round-trip between the client and the CA. It can also improve the security and privacy of the certificate validation by preventing potential attacks or tracking by malicious third parties. Verified

Reference:

https://en.wikipedia.org/wiki/OCSP_stapling

https://www.digicert.com/knowledgebase/ssl-certificates/ssl-general-topics/what-is-ocsp-stapling.html

https://www.entrust.com/knowledgebase/ssl/online-certificate-status-protocol-ocsp-stapling

asked 02/10/2024
Godavari, Rakesh
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first