General Security Concepts
268 soru
A network security administrator is commissioning a new internal web application server that requires a trusted SSL/TLS certificate signed by the enterprise internal Certificate Authority (CA). Which of the following sequences represents the correct chronological order of steps the administrator must perform to obtain and deploy this certificate?
Öğeleri doğru sıraya koymak için sürükleyin
An organization deploys a new RADIUS server to support 802.1X EAP-TLS authentication across corporate laptops. During testing, client devices fail to authenticate, reporting that the RADIUS server's identity cannot be verified. Analysis indicates that while client devices trust the organization's offline Root CA, the RADIUS server is transmitting only its leaf certificate, and clients cannot validate the intermediate issuing CA that signed it. Which of the following configuration changes on the server will resolve the authentication failure?
A systems engineer is implementing security controls for a enterprise API gateway that requires mutual TLS authentication. To optimize client connection speeds, the engineer wants to eliminate third-party real-time lookup latency during certificate revocation verification. Additionally, the engineer must request a new web server certificate following strict Public Key Infrastructure (PKI) enrollment best practices. Which of the following steps should the security engineer take to meet these requirements?
Geçerli olan tümünü seçin
An enterprise security administrator is deploying a high-traffic public web application server using TLS encryption. To minimize TLS handshake latency and prevent third-party tracking of user browsing habits caused by real-time client queries to an external Certificate Authority (CA), the administrator wants the web server to fetch and cache signed revocation status responses from the CA to append during the TLS handshake. Which of the following solutions should the administrator implement?
A DevOps engineer is setting up a secure internal web endpoint for a microservice and needs to enroll it into the organization's Public Key Infrastructure (PKI). Which of the following represents the correct sequential order of operational steps required to successfully obtain and deploy an X.509 certificate, from initial key creation to final service binding?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise systems specialist is configuring an automated build server to sign software packages using a newly established internal Public Key Infrastructure (PKI). Before requesting a digital certificate from the enterprise Certificate Authority (CA), the specialist must prepare a Certificate Signing Request (CSR) on the build server. Which of the following operations occurs on the build server prior to transmitting the CSR to the CA?
A security administrator is configuring digital certificates for an enterprise web gateway that host services for multiple subdomains across different domain names. To optimize TLS handshake performance, maintain client privacy, and ensure multi-domain validity, which TWO of the following configurations or steps should the administrator implement? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security administrator notices that after revoking a compromised employee device certificate, internal applications continue to trust the revoked certificate for up to 24 hours until the next scheduled status update file is generated. The administrator needs to update the PKI architecture so authentication services can query the revocation status of individual certificates in real time without forcing mobile clients to download complete revocation files over low-bandwidth cellular connections. Which of the following should the administrator implement to meet these requirements?