exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 852 discussion

Actual exam question from CompTIA's SY0-601
Question #: 852
Topic #: 1
[All SY0-601 Questions]

During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?

  • A. Updating the CRL
  • B. Patching the CA
  • C. Changing passwords
  • D. Implementing SOAR
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mikzer
Highly Voted 1 year ago
Selected Answer: A
Performed a search for CA patching, never came up. Going with A. Have to revoke the certificate and redo the process correctly. When a CA revokes a certificate, it updates the CRL. Then, the CRL is digitally signed by the issuer and distributed to all entities that rely on it. This process must run correctly, as errors can lead to significant security vulnerabilities. Related to Q#709.
upvoted 8 times
...
deejay2
Most Recent 3 months, 4 weeks ago
How do you patch a Certificate Authority (CA)?
upvoted 1 times
...
fb8c9bb
10 months, 1 week ago
Selected Answer: A
In the scenario described, a flaw in the internal PKI was exploited. The most relevant remediation task to address this specific issue would be to update the Certificate Revocation List (CRL). This would help in invalidating any compromised certificates and ensuring that they cannot be used again.
upvoted 1 times
...
Gigi42
10 months, 4 weeks ago
Invalid certificates are revoked. CA is a separate entity from the companies who request the services of obtaining certificates. So why is the company patching the CA?
upvoted 2 times
...
shady23
1 year ago
Selected Answer: B
Patching the Certificate Authority (CA) is the most critical remediation task in this scenario because the flaw in the internal PKI system was exploited to gain unauthorized access. By patching the CA, the organization can address the vulnerability that allowed the exploitation to occur in the first place. This action helps prevent similar attacks in the future by fixing the underlying security issue within the PKI infrastructure.
upvoted 3 times
...
Geronemo
1 year ago
Selected Answer: B
If the flaw in the internal PKI allowed an attacker to gain domain administrator rights using specially crafted certificates, it indicates a serious security vulnerability within the CA infrastructure. Patching the CA involves fixing the vulnerability by applying software updates, security patches, or configuration changes to eliminate the exploited flaw. This helps prevent similar attacks in the future and ensures the integrity and security of the PKI. Similarly, updating the Certificate Revocation List (CRL) (option A) is important for revoking compromised certificates, but it does not address the underlying flaw in the PKI.
upvoted 2 times
...
Ravnit
1 year, 1 month ago
B is correct In this scenario, exploiting a flaw in the internal PKI system led to unauthorized access and the elevation of privileges. To prevent similar incidents in the future, it is crucial to address the root cause of the vulnerability, which in this case is the flaw in the Certificate Authority (CA)
upvoted 2 times
...
paCer66
1 year, 1 month ago
B. Pentest-cleanup-remediation (CA patching)-final control retest.
upvoted 2 times
...
CircaG
1 year, 1 month ago
Selected Answer: B
B. In this scenario, the exploitation involved a flaw in the internal Public Key Infrastructure (PKI). Patching the Certificate Authority (CA) is crucial to address this vulnerability and prevent similar exploits in the future. By patching the CA software, any known security vulnerabilities or weaknesses can be addressed, enhancing the overall security of the PKI infrastructure.
upvoted 1 times
Why isn't it A? A seems to be a good part of cleanup, revoking the specially crafted certificates
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago