exam questions

Exam CAS-005 All Questions

View all questions & answers for the CAS-005 exam

Exam CAS-005 topic 1 question 44 discussion

Actual exam question from CompTIA's CAS-005
Question #: 44
Topic #: 1
[All CAS-005 Questions]

A security architect wants to ensure a remote host's identity and decides that pinning the X.509 certificate to the device is the most effective solution. Which of the following must happen first?

  • A. Use Distinguished Encoding Rules (DER) for the certificate.
  • B. Extract the private key from the certificate.
  • C. Use an out-of-band method to obtain the certificate.
  • D. Compare the retrieved certificate with the embedded certificate.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vicbersong
1 week, 1 day ago
Selected Answer: C
❌ Why the others are incorrect: A. Use Distinguished Encoding Rules (DER) DER is a binary format for encoding certificates, but it's not a required first step and doesn't ensure trust by itself. B. Extract the private key from the certificate This is not only unnecessary but also a serious security violation. The private key should never be extracted or shared. D. Compare the retrieved certificate with the embedded certificate This is the verification step, which happens after pinning — not before.
upvoted 1 times
...
vicbersong
1 week, 1 day ago
Selected Answer: C
✅ C. Use an out-of-band method to obtain the certificate. 🔐 Explanation: Certificate pinning is a security technique used to associate a host (e.g., a server) with its expected X.509 certificate or public key. This helps prevent man-in-the-middle (MitM) attacks where an attacker could present a fraudulent certificate. Before you can "pin" a certificate (i.e., embed or store a known-good certificate or public key in the app or system): You first need to obtain the correct certificate securely, usually via an out-of-band method (i.e., not over the same channel that could be compromised). Once you have the authentic certificate, you can pin it, and then compare it at runtime against what is presented by the host.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago