The private key for a website was stolen, and a new certificate has been issued. Which of the following needs to be updated next?
Choose an answer
Tap an option to check your answer.
Correct answer: CRL.
Why this is the answer
When a private key is compromised, the associated certificate becomes untrustworthy and must be revoked. The Certificate Revocation List (CRL) is the mechanism used by Certificate Authorities (CAs) to publish a list of digital certificates that have been revoked before their scheduled expiration date. Updating the CRL ensures that relying parties (clients) are aware that the old certificate is no longer valid and should not be trusted. OCSP (Online Certificate Status Protocol) is an alternative to CRL for checking certificate status in real-time, but the CRL itself still needs to be updated by the CA. SCEP (Simple Certificate Enrollment Protocol) is for enrolling certificates, and CSR (Certificate Signing Request) is for requesting a certificate; neither directly addresses the need to invalidate a compromised certificate.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed