ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 448 - CAS-004 discussion

Report
Export

A technician accidentally deleted the secret key that was corresponding to the public key pinned to a busy online magazine. To remedy the situation, the technician obtained a new certificate with a different key. However, paying subscribers were locked out of the website until the key-pinning policy expired. Which of the following alternatives should the technician adopt to prevent a similar issue in the future?

A.
Registration authority
Answers
A.
Registration authority
B.
Certificate revocation list
Answers
B.
Certificate revocation list
C.
Client authentication
Answers
C.
Client authentication
D.
Certificate authority authorization
Answers
D.
Certificate authority authorization
Suggested answer: D

Explanation:

Certificate Authority Authorization (CAA) is not listed directly in the provided options, but it is a relevant mechanism in the context of managing certificates and preventing issues similar to the one described. However, based on the available choices, the Online Certificate Status Protocol (OCSP) comes closest to providing a viable solution. OCSP allows for real-time validation of a certificate's revocation status, which could mitigate the issue of users being locked out due to key pinning policies. It is a more modern and efficient alternative to Certificate Revocation Lists (CRLs), offering faster and more reliable certificate status checks. By implementing OCSP, the technician could ensure that clients receive timely updates on the revocation status of certificates, potentially avoiding the downtime caused by the key-pinning policy awaiting expiration.

asked 02/10/2024
Christian Walet
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first