ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 490 - CAS-004 discussion

Report
Export

The IT team suggests the company would save money by using self-signed certificates, but the security team indicates the company must use digitally signed third-party certificates. Which of the following is a valid reason to pursue the security team's recommendation?

A.
PKCS #10 is still preferred over PKCS #12.
Answers
A.
PKCS #10 is still preferred over PKCS #12.
B.
Private-key CSR signage prevents on-path interception.
Answers
B.
Private-key CSR signage prevents on-path interception.
C.
There is more control in using a local certificate over a third-party certificate.
Answers
C.
There is more control in using a local certificate over a third-party certificate.
D.
There is minimal benefit in using a certificate revocation list.
Answers
D.
There is minimal benefit in using a certificate revocation list.
Suggested answer: B

Explanation:

Digitally signed third-party certificates provide greater security assurance because they are verified by trusted Certificate Authorities (CAs) and offer protection against on-path (man-in-the-middle) interception. Private-key Certificate Signing Request (CSR) signage helps ensure that communication cannot be intercepted or modified by malicious actors. Self-signed certificates, on the other hand, are not trusted outside the local environment and do not provide the same level of protection against on-path attacks. CASP+ emphasizes the security benefits of using third-party-signed certificates for securing communications over public networks.

CASP+ CAS-004 Exam Objectives: Domain 3.0 -- Enterprise Security Architecture (PKI, SSL/TLS Certificates)

CompTIA CASP+ Study Guide: The Role of Certificate Authorities in Secure Communication

asked 02/10/2024
Lucile Jeanneret
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first