Soru

Zorluk: OrtaPublic Key Infrastructure and Certificate Management

An enterprise security administrator notices that after revoking a compromised employee device certificate, internal applications continue to trust the revoked certificate for up to 24 hours until the next scheduled status update file is generated. The administrator needs to update the PKI architecture so authentication services can query the revocation status of individual certificates in real time without forcing mobile clients to download complete revocation files over low-bandwidth cellular connections. Which of the following should the administrator implement to meet these requirements?

  1. Online Certificate Status Protocol (OCSP)Cevap
  2. B
    Certificate Revocation List (CRL) Distribution Points
  3. C
    Key Escrow storage
  4. D
    Bulk symmetric key rotation

Cevap

Online Certificate Status Protocol (OCSP)
The correct option is Online Certificate Status Protocol (OCSP). OCSP allows services to submit a lightweight request containing a specific certificate's serial number to an OCSP responder and receive an immediate status response (Good, Revoked, or Unknown). This eliminates the time delay associated with scheduled list publications and conserves cellular bandwidth compared to downloading entire lists.

Adım Adım Çözüm

1
Analyze the operational limitation in the scenario
The current setup suffers from a 24-hour update latency window and excessive bandwidth consumption due to periodic downloading of entire revocation lists.
Certificate Revocation Lists (CRLs) are published on a timed schedule and contain all revoked certificate serial numbers, making them bandwidth-heavy and delayed.
2
Identify the PKI mechanism designed for low-bandwidth, real-time single certificate status checks
Online Certificate Status Protocol (OCSP) provides real-time verification status (good, revoked, or unknown) for a specific certificate query.
OCSP sends lightweight requests and responses for individual certificate serial numbers rather than transferring complete lists.

Anahtar Kavram

Certificate Revocation and Real-time Status Validation (OCSP vs CRL)
Bu soruyu puanla