Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 272 discussion

Actual exam question from ISC's CISSP
Question #: 272
Topic #: 1
[All CISSP Questions]

Which of the following is the MOST common use of the Online Certificate Status Protocol (OCSP)?

  • A. To verify the validity of an X.509 digital certificate
  • B. To obtain the expiration date of an X.509 digital certificate
  • C. To obtain the revocation status of an X.509 digital certificate
  • D. To obtain the author name of an X.509 digital certificate
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
rdy4u
Highly Voted 2 years ago
Selected Answer: C
The Online Certificate Status Protocol (OCSP) is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate.
upvoted 9 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
franbarpro
Highly Voted 2 years, 1 month ago
It's in the name Online Certificate Status Protocol (OCSP) - we want to check the "status" of a cert!
upvoted 5 times
...
TheManiac
Most Recent 6 months, 1 week ago
Selected Answer: C
The Online Certificate Status Protocol (OCSP) is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate.
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
A. To verify the validity of an X.509 digital certificate ......this is the best answer choice. OCSP is used to check validity of digital certifications. C. is a distraction by the use of the word "status". Answer A. encompasses C which makes it the best answer choice.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
I thought the OCSP was an upgrade from CRL and gave more than just the revocation status. ChatGPT gave answer C as well so I will go with that but I have my doubts.
upvoted 1 times
...
Danny168
1 year, 5 months ago
Selected Answer: A Online Certificate Status Protocol (OCSP) This protocol eliminates the latency inherent in the use of certificate revocation lists by providing a means for real-time certificate verification. When a client receives a certificate, it sends an OCSP request to the CA’s OCSP server. The server then responds with a status of valid, invalid, or unknown. The browser uses this information to determine whether the certificate is valid.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
A. To verify the validity of an X.509 digital certificate "The Online Certificate Status Protocol (OCSP) is an alternative to the certificate revocation list (CRL) and is used to check whether a digital certificate is valid or if it has been revoked." https://www.fortinet.com/resources/cyberglossary/ocsp#:~:text=The%20Online%20Certificate%20Status%20Protocol%20(OCSP)%20is%20an%20alternative%20to,if%20it%20has%20been%20revoked. C is included in A. When I check certificates I check the status, not if it's revoked or not. Commands in general have a "status" flag, I don't recall ever seeing a "revoked" type option.
upvoted 2 times
...
jbell
1 year, 7 months ago
Selected Answer: C
From the relevant RFC (RFC 6960) which is definitive: The Online Certificate Status Protocol (OCSP) enables applications to determine the (revocation) state of identified certificates. OCSP may be used to satisfy some of the operational requirements of providing more timely revocation information than is possible with CRLs and may also be used to obtain additional status information. An OCSP client issues a status request to an OCSP responder and suspends acceptance of the certificates in question until the responder provides a response.
upvoted 1 times
...
Goseu
1 year, 7 months ago
Selected Answer: A
Simply A , Google it.
upvoted 1 times
...
RVoigt
1 year, 9 months ago
Selected Answer: A
CISSP Official Study Gude pg 282 "Online Certificate Status Protocol (OCSP) This protocol eliminates the latency inherent in the use of certificate revocation lists by providing a means for real- time certificate verification. When a client receives a certificate, it sends an OCSP request to the CA's OCSP server. The server then responds with a status of valid, invalid, or unknown. The browser uses this information to determine whether the certificate is valid. "
upvoted 2 times
...
crishnamohan
1 year, 9 months ago
Selected Answer: A
(OCSP)   This protocol eliminates the latency inherent in the use of certificate revocation lists by providing a means for real-time certificate verification. When a client receives a certificate, it sends an OCSP request to the CA's OCSP server. The server then responds with a status of valid, invalid, or unknown. The browser uses this information to determine whether the certificate is valid.
upvoted 3 times
...
Delab202
1 year, 11 months ago
Selected Answer: C
Online Certificate Status Protocol (OCSP) A request/response protocol used over HTTP. A client uses OCSP to contact the CA directly and ask about the revocation status of a particular certificate. Since an OCSP request is much smaller than a full CRL, this can save significantly on network resources, and since it doesn’t rely on publication periods, it can always be up to date. For these reasons, OCSP is generally seen as a more flexible and modern alternative to CRL.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...