PKI Flaw Remediation: Patching the CA
During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?
Community Votes
60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of remediation vs. mitigation; the trap is updating the CRL which only handles current certificates, not the underlying software flaw.
When a PKI flaw is exploited, patching the Certificate Authority (CA) addresses the root cause. This prevents future exploitation of the same vulnerability.
Many choose Updating the CRL because it invalidates compromised certs, but it does not fix the exploitable flaw in the CA software itself.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Patching the CA (Option B) is the correct remediation because it fixes the underlying vulnerability that allowed the attacker to craft malicious certificates. Without patching the software or configuration flaw, the attacker could simply create new fraudulent certificates at any time.Why the Other Options Are Wrong
Updating the CRL (Option A) is a mitigation step to invalidate currently issued bad certificates, but it does not stop the attacker from issuing new ones if the flaw remains. Changing passwords (Option C) helps contain the breach but doesn't secure the PKI infrastructure. SOAR (Option D) is for automation and response, not infrastructure remediation.Community Comment Notes
Community comments are split, with some correctly identifying patching as the root cause fix while others mistakenly prioritize CRL updates. As user shady23 noted, 'Patching the Certificate Authority (CA) is the most critical remediation task... because the flaw... was exploited.' Conversely, mikzer argues for CRL, stating 'Have to revoke the certificate and redo the process correctly,' missing the need to fix the CA itself.Exam Strategy
Always distinguish between 'remediation' (fixing the root cause) and 'mitigation' (reducing impact). If a system component has a 'flaw', fixing that component (patching/updating) is usually the primary remediation goal.
Frequently Asked Questions
Why isn't updating the CRL the best remediation?
Updating the CRL only revokes existing compromised certificates. It does not fix the software flaw allowing attackers to create new fraudulent certificates.
Does patching the CA require downtime?
Yes, patching often requires maintenance windows. However, it is necessary to permanently close the vulnerability exploited by the attacker.