ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 457 - CAS-004 discussion

Report
Export

A security analyst is reviewing the following output from a vulnerability scan from an organization's internet-facing web services:

Which of the following indicates a susceptibility whereby an attacker can take advantage of the trust relationship between the client and the server?

A.
Line 06
Answers
A.
Line 06
B.
Line 10
Answers
B.
Line 10
C.
Line 13
Answers
C.
Line 13
D.
Line 17
Answers
D.
Line 17
Suggested answer: A

Explanation:

The scan output in line 06 indicates that OCSP Must-Staple is not supported. This vulnerability exposes the application to attacks where an attacker can exploit the trust relationship between the client and the server by forging certificate revocation statuses. When OCSP stapling is not enforced, a client cannot reliably check if a certificate has been revoked, potentially allowing attackers to exploit this gap. CASP+ discusses the importance of certificate validation mechanisms such as OCSP (Online Certificate Status Protocol) to prevent man-in-the-middle and trust-exploiting attacks.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Certificate Validation, OCSP)

CompTIA CASP+ Study Guide: Secure Web Services and Trust Relationships

asked 02/10/2024
Michael Costello
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first