How to Remediate a Compromised Internal PKI After a Pen Test?
During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?
Community Votes
55% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of permanent remediation versus temporary containment in incident response, with the trap being the assumption that updating the CRL alone fully resolves a systemic PKI vulnerability.
This question addresses post-penetration testing remediation for a flawed internal PKI, focusing on whether to patch the Certificate Authority or update the CRL. While candidates split between immediate certificate revocation and root cause mitigation, the official guidance prioritizes patching the vulnerable CA to permanently resolve the exploit vector.
Many candidates select 'Updating the CRL' because revoking compromised certificates provides immediate threat containment, but this only mitigates already-issued malicious certificates without addressing the underlying CA software flaw that allowed their creation.
Community Discussion (19 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: PKI Vulnerability Remediation
During a penetration test, discovering a flaw in an internal Public Key Infrastructure (PKI) requires structured remediation. The question specifically asks for a task completed during the cleanup phase of remediation. In CompTIA Security+ terminology, cleanup and remediation overlap significantly when addressing identified vulnerabilities; the goal is to restore the environment to a secure state and eliminate the attack vector. Patching the Certificate Authority (CA) directly addresses the exploited flaw, ensuring that attackers cannot generate additional malicious certificates using the same vulnerability. As noted by multiple candidates, while revocation mechanisms are important, they do not fix the underlying software defect.Why Updating the CRL is a Common Trap
Many examinees choose updating the CRL because it immediately invalidates compromised certificates and blocks further authentication attempts. This is a valid containment step, but it functions more as an emergency response or eradication measure rather than a complete remediation fix. Without patching the CA, the system remains vulnerable to new certificate forgery. Community discussions highlight this distinction, with several users noting that while both actions may occur, patching resolves the root cause and aligns best with permanent remediation goals.Why Changing Passwords and SOAR Are Incorrect
Changing passwords does not address the certificate-based authentication exploit at its source, though credential rotation may be part of broader post-compromise procedures. Implementing SOAR (Security Orchestration, Automation, and Response) is an architectural enhancement for incident management, not a direct remediation task for a specific PKI flaw. These options distract from the immediate technical fix required for the vulnerable infrastructure component.Official Reference
Exam Strategy
When questions ask about remediation or cleanup after finding a vulnerability, prioritize solutions that eliminate the root cause over those that only mitigate symptoms. Look for keywords like "flaw," "exploited," or "vulnerability" paired with "remediation"—these typically point to configuration fixes, patches, or architectural changes rather than temporary workarounds.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →