How to Remediate a Compromised Internal PKI After a Pen Test?

During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?

  1. Updating the CRL
  2. Patching the CA Source Reference Answer
  3. Changing passwords
  4. Implementing SOAR

Community Votes

B
55%
A
45%

55% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of permanent remediation versus temporary containment in incident response, with the trap being the assumption that updating the CRL alone fully resolves a systemic PKI vulnerability.

This question addresses post-penetration testing remediation for a flawed internal PKI, focusing on whether to patch the Certificate Authority or update the CRL. While candidates split between immediate certificate revocation and root cause mitigation, the official guidance prioritizes patching the vulnerable CA to permanently resolve the exploit vector.

Many candidates select 'Updating the CRL' because revoking compromised certificates provides immediate threat containment, but this only mitigates already-issued malicious certificates without addressing the underlying CA software flaw that allowed their creation.

Community Discussion (19 comments)

baronvon 👍 12 Selected: B
B. Patching the CA Here's why: Patching the Certificate Authorities: This involves updating the CA software to address the specific vulnerability that was exploited. Since the attack exploited a flaw in the PKI, patching the CA is crucial to fixing the vulnerability and preventing similar attacks in the future. While the other options are also important in a broader security context, they may not directly address the specific issue with the PKI flaw: -Updating the Certificate Revocation Lists (CRLs): This is important for managing revoked certificates but may not address the root cause of the PKI vulnerability. -Changing passwords: This is a good security practice but would not resolve the underlying issue with the PKI vulnerability. -Implementing SOAR (Security Orchestration, Automation, and Response): SOAR can help with automating responses and managing security operations but does not directly address the specific PKI vulnerability. -Therefore, patching the Certificate Authorities is the most effective and direct remediation task for this situatio
Ty13 👍 10 Selected: A
A. Updating the CRL It's a really bad question because you would do BOTH A and B. The only reason I'm saying A is because the question specifically says "cleanup phase". Patching the CA would TECHNICALLY fall under the Eradication Phase - we're eradicating a threat (patching a vulnerable CA server) - and then cleanup would be updating the CRL.
Ashtom 👍 1 Selected: A
the ca is not a software that can be patched. its an entity/org
9149f41 👍 1 Selected: B
CRL is for revocation; this way we can reissue the certificate and resolve the issue as well. But it does not underlying vulnerability in the CA itself. The question tells to cleanup the phase, which is more accurate with just patching the existing CA.
ramzie 👍 1 Selected: A
Answer is A Update the CRL because Immediately invalidates compromised certificates Prevents further use of malicious certificates Blocks certificate-based authentication attempts Part of proper PKI hygiene after compromise WHy not B Patching the CA Important but secondary to immediate threat Doesn't address already issued certificates Long-term solution rather than immediate cleanup Doesn't stop current compromise
laternak26 👍 2 Selected: B
B. Patching the CA: The flaw in the internal Public Key Infrastructure (PKI) was exploited during the penetration test to gain domain administrator rights, which indicates a vulnerability within the Certificate Authority (CA) system. To prevent similar attacks in the future, the CA should be patched to fix any identified vulnerabilities in the certificate issuance process. This is a critical step in remediating the flaw and securing the PKI system against further exploitation. Why NOT: A. Updating the CRL (Certificate Revocation List): While updating the CRL is important to revoke any compromised or malicious certificates, it addresses only the symptom (the specific certificates) rather than the root cause (the vulnerability in the CA). The flaw that allowed for the exploitation needs to be patched first, as it could enable the attacker to issue more certificates in the future.
AndyK2 👍 1 Selected: B
B. Patching the CA
MikelMiguel 👍 1 Selected: B
The cleanup phase in a penetration test refers to the steps taken after the test has been completed to ensure that any changes made during the testing process are reversed, and the environment is restored to its original state. This phase ensures that no trace of the penetration test remains and that any potential security risks introduced during the test are mitigated. In the context of the remediation task in question, the cleanup phase focuses on fixing the vulnerabilities exploited during the penetration test and ensuring the security of the system moving forward. For example, patching the Certification Authority (CA) if it was the root cause of the domain administrator privilege escalation would be a critical task during this phase.
fmeox567 👍 1 Selected: B
The correct answer is: B. Patching the CA GPT
cyberWoof 👍 1 Selected: A
Updating the CRL
Emmyrajj 👍 1 Selected: A
The correct answer is: A. Updating the CRL (Certificate Revocation List) Explanation: When a flaw in the PKI (Public Key Infrastructure) is exploited, especially involving malicious or compromised certificates, the first step in remediation is to revoke the affected certificates to prevent further misuse. This is done by updating the Certificate Revocation List (CRL) or using Online Certificate Status Protocol (OCSP). This ensures that any certificate used in the attack is marked as invalid, mitigating the risk of continued exploitation.
9ef4a35 👍 1
A. Updating the CRL
Murtuza 👍 1 Selected: B
Patching the CA
User92 👍 1 Selected: B
Updating the CRL is also important, but it primarily deals with revoking compromised certificates rather than fixing the underlying vulnerability.
tamdod 👍 2
This occurred during a penetration test. We should patch the CA first to prevent further exploitation, that ensures no new certificates can be issued using the same flaw. The we would update the CRL.
TrebleSmith 👍 3 Selected: A
While patching the Certificate Authority is important to prevent a similar attack in the future, I believe that updating the Certificate Revocation List will apply more directly to the clean-up phase.
suleman1000 👍 1 Selected: B
B: Patching the CA
salahsami2002 👍 1
B. Patching the CA (Certificate Authority) Since the flaw in the internal Public Key Infrastructure (PKI) was exploited to gain domain administrator rights, the primary remediation task should be to patch the Certificate Authority (CA). This will address the vulnerability that allowed the exploitation of the PKI system. Other tasks like updating the Certificate Revocation List (CRL) may be necessary, but patching the CA will directly resolve the issue that led to the compromise.
a4e15bd 👍 5
A. Update the CRL is correct The first priority is to revoke any compromise certificates. This ensures that those certificates can no longer be used for unauthorized access.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: PKI Vulnerability Remediation

During a penetration test, discovering a flaw in an internal Public Key Infrastructure (PKI) requires structured remediation. The question specifically asks for a task completed during the cleanup phase of remediation. In CompTIA Security+ terminology, cleanup and remediation overlap significantly when addressing identified vulnerabilities; the goal is to restore the environment to a secure state and eliminate the attack vector. Patching the Certificate Authority (CA) directly addresses the exploited flaw, ensuring that attackers cannot generate additional malicious certificates using the same vulnerability. As noted by multiple candidates, while revocation mechanisms are important, they do not fix the underlying software defect.

Why Updating the CRL is a Common Trap

Many examinees choose updating the CRL because it immediately invalidates compromised certificates and blocks further authentication attempts. This is a valid containment step, but it functions more as an emergency response or eradication measure rather than a complete remediation fix. Without patching the CA, the system remains vulnerable to new certificate forgery. Community discussions highlight this distinction, with several users noting that while both actions may occur, patching resolves the root cause and aligns best with permanent remediation goals.

Why Changing Passwords and SOAR Are Incorrect

Changing passwords does not address the certificate-based authentication exploit at its source, though credential rotation may be part of broader post-compromise procedures. Implementing SOAR (Security Orchestration, Automation, and Response) is an architectural enhancement for incident management, not a direct remediation task for a specific PKI flaw. These options distract from the immediate technical fix required for the vulnerable infrastructure component.

Official Reference

Exam Strategy

When questions ask about remediation or cleanup after finding a vulnerability, prioritize solutions that eliminate the root cause over those that only mitigate symptoms. Look for keywords like "flaw," "exploited," or "vulnerability" paired with "remediation"—these typically point to configuration fixes, patches, or architectural changes rather than temporary workarounds.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide