During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?
Choose an answer
Tap an option to check your answer.
Correct answer: Patching the CA.
Why this is the answer
Patching the CA is the correct remediation. The exploit leveraged a flaw in the internal Public Key Infrastructure (PKI) to create specially crafted certificates, indicating a vulnerability within the Certificate Authority (CA) itself. Patching the CA directly addresses this underlying flaw, preventing similar attacks in the future. Updating the Certificate Revocation List (CRL) is a good practice for invalidating compromised certificates, but it doesn't fix the root cause of the vulnerability that allowed the certificates to be created in the first place. Changing passwords is important for compromised accounts, but again, it doesn't resolve the PKI flaw. Implementing Security Orchestration, Automation, and Response (SOAR) is a broader security improvement strategy that could help with incident response, but it's not the direct remediation for a specific CA vulnerability.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed