Which Protocol Validates a Digital Certificate Upon Presentation?
Which of the following is used to validate a certificate when it is presented to a user?
Community Votes
68% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your knowledge of PKI verification workflows, with the common trap being the selection of the Certificate Authority instead of the real-time validation protocol.
Online Certificate Status Protocol (OCSP) is the standard mechanism for real-time certificate validation and revocation checking. The candidate community overwhelmingly agrees that OCSP is the correct answer, distinguishing the active validation tool from the issuing authority.
Option C (CA) is the most frequent incorrect choice because test-takers often conflate the organization that issues certificates with the specific protocol required to verify their live status during a connection.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
OCSP (Online Certificate Status Protocol) is explicitly engineered to query the revocation status of a digital certificate in real time. When a user or system presents a certificate, the client contacts an OCSP responder to confirm whether the CA has revoked it prior to expiration. This dynamic verification ensures immediate trust assessment without waiting for periodic updates. As highlighted in the discussion, OCSP functions as the active enforcement layer that validates certificates upon presentation.Why the Other Options Are Wrong
A Certificate Authority (CA) is responsible for issuing, signing, and maintaining the lifecycle of certificates, but it does not perform the continuous validation step itself. A Certificate Signing Request (CSR) is simply a formatted data block used to request a certificate, offering no validation capability whatsoever. CRC (Cyclic Redundancy Check) is a basic error-detection algorithm for data transmission integrity and holds no relevance to public key infrastructure. These options serve as classic distractors to separate those who understand PKI architecture from those who only recognize the term certificate.Community Comment Notes
Several contributors like [1] and [4] effectively illustrate the difference by comparing the CA to a lawmaking body that creates records and OCSP to police that actively enforces and checks them. Users [3], [5], and [6] consistently point out that OCSP delivers up-to-the-minute status checks, directly answering the scenario where a certificate is presented. Although a minority initially voted for the CA due to ambiguous phrasing [2], the prevailing consensus correctly identifies OCSP as the operational validation mechanism expected on the exam.Official Reference
Exam Strategy
Master the distinct responsibilities within PKI ecosystems by mapping each component to its exact function. Whenever a SY0-701 question mentions real-time validation, revocation checking, or verifying a certificate during a session, immediately discard the CA and select the protocol (OCSP) or list (CRL) mechanism.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →