PKI Flaw Remediation: Patching the CA

Vulnerability Management
Answer Correct answer: B — Patching the CA to address the underlying security vulnerability in the certificate authority infrastructure.

During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?

  1. Updating the CRL
  2. Patching the CA Correct Answer
  3. Changing passwords
  4. Implementing SOAR

Community Votes

A
60%
B
40%

60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of remediation vs. mitigation; the trap is updating the CRL which only handles current certificates, not the underlying software flaw.

When a PKI flaw is exploited, patching the Certificate Authority (CA) addresses the root cause. This prevents future exploitation of the same vulnerability.

Many choose Updating the CRL because it invalidates compromised certs, but it does not fix the exploitable flaw in the CA software itself.

Community Discussion (9 comments)

mikzer 👍 8 Selected: A
Performed a search for CA patching, never came up. Going with A. Have to revoke the certificate and redo the process correctly. When a CA revokes a certificate, it updates the CRL. Then, the CRL is digitally signed by the issuer and distributed to all entities that rely on it. This process must run correctly, as errors can lead to significant security vulnerabilities. Related to Q#709.
deejay2 👍 1
How do you patch a Certificate Authority (CA)?
fb8c9bb 👍 1 Selected: A
In the scenario described, a flaw in the internal PKI was exploited. The most relevant remediation task to address this specific issue would be to update the Certificate Revocation List (CRL). This would help in invalidating any compromised certificates and ensuring that they cannot be used again.
Gigi42 👍 2
Invalid certificates are revoked. CA is a separate entity from the companies who request the services of obtaining certificates. So why is the company patching the CA?
shady23 👍 3 Selected: B
Patching the Certificate Authority (CA) is the most critical remediation task in this scenario because the flaw in the internal PKI system was exploited to gain unauthorized access. By patching the CA, the organization can address the vulnerability that allowed the exploitation to occur in the first place. This action helps prevent similar attacks in the future by fixing the underlying security issue within the PKI infrastructure.
Geronemo 👍 2 Selected: B
If the flaw in the internal PKI allowed an attacker to gain domain administrator rights using specially crafted certificates, it indicates a serious security vulnerability within the CA infrastructure. Patching the CA involves fixing the vulnerability by applying software updates, security patches, or configuration changes to eliminate the exploited flaw. This helps prevent similar attacks in the future and ensures the integrity and security of the PKI. Similarly, updating the Certificate Revocation List (CRL) (option A) is important for revoking compromised certificates, but it does not address the underlying flaw in the PKI.
Ravnit 👍 2
B is correct In this scenario, exploiting a flaw in the internal PKI system led to unauthorized access and the elevation of privileges. To prevent similar incidents in the future, it is crucial to address the root cause of the vulnerability, which in this case is the flaw in the Certificate Authority (CA)
paCer66 👍 2
B. Pentest-cleanup-remediation (CA patching)-final control retest.
CircaG 👍 1 Selected: B
B. In this scenario, the exploitation involved a flaw in the internal Public Key Infrastructure (PKI). Patching the Certificate Authority (CA) is crucial to address this vulnerability and prevent similar exploits in the future. By patching the CA software, any known security vulnerabilities or weaknesses can be addressed, enhancing the overall security of the PKI infrastructure.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Patching the CA (Option B) is the correct remediation because it fixes the underlying vulnerability that allowed the attacker to craft malicious certificates. Without patching the software or configuration flaw, the attacker could simply create new fraudulent certificates at any time.

Why the Other Options Are Wrong

Updating the CRL (Option A) is a mitigation step to invalidate currently issued bad certificates, but it does not stop the attacker from issuing new ones if the flaw remains. Changing passwords (Option C) helps contain the breach but doesn't secure the PKI infrastructure. SOAR (Option D) is for automation and response, not infrastructure remediation.

Community Comment Notes

Community comments are split, with some correctly identifying patching as the root cause fix while others mistakenly prioritize CRL updates. As user shady23 noted, 'Patching the Certificate Authority (CA) is the most critical remediation task... because the flaw... was exploited.' Conversely, mikzer argues for CRL, stating 'Have to revoke the certificate and redo the process correctly,' missing the need to fix the CA itself.

Exam Strategy

Always distinguish between 'remediation' (fixing the root cause) and 'mitigation' (reducing impact). If a system component has a 'flaw', fixing that component (patching/updating) is usually the primary remediation goal.

Frequently Asked Questions

Why isn't updating the CRL the best remediation?

Updating the CRL only revokes existing compromised certificates. It does not fix the software flaw allowing attackers to create new fraudulent certificates.

Does patching the CA require downtime?

Yes, patching often requires maintenance windows. However, it is necessary to permanently close the vulnerability exploited by the attacker.

Related Analysis

← Back to SY0-601 Study Guide