Which Protocol Validates a Digital Certificate Upon Presentation?

PKI & Certificate Management

Which of the following is used to validate a certificate when it is presented to a user?

  1. OCSP Source Reference Answer
  2. CSR
  3. CA
  4. CRC

Community Votes

A
68%
C
32%

68% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your knowledge of PKI verification workflows, with the common trap being the selection of the Certificate Authority instead of the real-time validation protocol.

Online Certificate Status Protocol (OCSP) is the standard mechanism for real-time certificate validation and revocation checking. The candidate community overwhelmingly agrees that OCSP is the correct answer, distinguishing the active validation tool from the issuing authority.

Option C (CA) is the most frequent incorrect choice because test-takers often conflate the organization that issues certificates with the specific protocol required to verify their live status during a connection.

Community Discussion (14 comments)

c80f5c5 👍 44
CA issues and manages certificates. OSCP - Online Certificate Status Protocol, a protocol that checks a certificate for validity and if its been revoked (by the CA). The answer is OSCP. CA is like Congress, OSCP is like police. Congress records laws and writes them but don't actually enforce anything. Police enforce them
braveheart22 👍 3 Selected: A
A is the right answer from my point of view. OCSP (Online Certificate Status Protocol): OCSP is used to validate the revocation status of a digital certificate. When a certificate is presented to a user, OCSP allows the recipient to query the Certificate Authority (CA) in real time to check if the certificate has been revoked before its expiration date. This is especially useful for determining whether a certificate is still valid or if it has been revoked due to compromise or other reasons. Relevant to the question: OCSP helps in validating the revocation status of a certificate when it is presented.
2fd1029 👍 1 Selected: A
Gotta be A. Can't be the CA because the CA issues the certs but isn't referred to for validating them, that's the CRL or OCSP.
Cee007 👍 1 Selected: A
A OCSP
a4e15bd 👍 2
It is A OCSP This is a mechanism used to check the validity of a certificate in real time. When a certificate is presented, the user's system queries the OCSP responder to verify that the certificate is still valid and has not be revoked by CA. The CA is responsible for issuing, revoking and managing digital certificates, but it does not perform the real time validation of the certificates.
chasingsummer 👍 1 Selected: A
I don't think they are trying to trick us. I pick the simple answer.
Crucible_Bro 👍 1 Selected: A
A. Online Certificate Status Protocol is the actual protocol that is validating the request. A CA simply managaes those validations.
dbrowndiver 👍 2 Selected: A
When a certificate is presented to a user as written in the scenario(e.g., when visiting a secure website), the system can use OCSP to query the CA’s OCSP responder. This helps determine whether the certificate is still valid or has been revoked. -Real-Time Validation: Unlike Certificate Revocation Lists (CRLs), which are static lists of revoked certificates, OCSP provides dynamic, up-to-date information about the certificate’s status, allowing for timely detection of compromised or invalid certificates. Why this is the best fit: Security Assurance: By using OCSP, systems can ensure that a presented certificate is not only genuine but also has not been revoked due to compromise or other reasons. This real-time validation is critical for maintaining secure communications.
WOW_ThatsCrazy 👍 2 Selected: A
OCSP is used to validate the status of a digital certificate in real-time. When a certificate is presented to a user, the OCSP responder can be queried to check if the certificate is still valid or if it has been revoked. This provides a more efficient and timely method of certificate validation compared to traditional CRL (Certificate Revocation List) checks.
Etc_Shadow28000 👍 2 Selected: A
A. OCSP (Online Certificate Status Protocol) OCSP is used to validate a certificate when it is presented to a user by checking the certificate's revocation status. It provides real-time status information about the validity of a certificate, ensuring that it has not been revoked. Therefore, the correct answer is: A. OCSP
drosas84 👍 4 Selected: C
the question is tricky. It is basically asking what is "used" to validate a certificate when it is presented to a user. Meaning, what do you use to validate a certificate when giving it to a user to use? a CA. An OCSP checks whether a certificate is valid or revoked, it doesn't validate a certificate. This is how I read the question.
edmondme 👍 1 Selected: A
They are looking for the protocol OCSP
Shaman73 👍 1 Selected: A
A. OCSP
123456789User 👍 3 Selected: C
Certificate Authority

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

OCSP (Online Certificate Status Protocol) is explicitly engineered to query the revocation status of a digital certificate in real time. When a user or system presents a certificate, the client contacts an OCSP responder to confirm whether the CA has revoked it prior to expiration. This dynamic verification ensures immediate trust assessment without waiting for periodic updates. As highlighted in the discussion, OCSP functions as the active enforcement layer that validates certificates upon presentation.

Why the Other Options Are Wrong

A Certificate Authority (CA) is responsible for issuing, signing, and maintaining the lifecycle of certificates, but it does not perform the continuous validation step itself. A Certificate Signing Request (CSR) is simply a formatted data block used to request a certificate, offering no validation capability whatsoever. CRC (Cyclic Redundancy Check) is a basic error-detection algorithm for data transmission integrity and holds no relevance to public key infrastructure. These options serve as classic distractors to separate those who understand PKI architecture from those who only recognize the term certificate.

Community Comment Notes

Several contributors like [1] and [4] effectively illustrate the difference by comparing the CA to a lawmaking body that creates records and OCSP to police that actively enforces and checks them. Users [3], [5], and [6] consistently point out that OCSP delivers up-to-the-minute status checks, directly answering the scenario where a certificate is presented. Although a minority initially voted for the CA due to ambiguous phrasing [2], the prevailing consensus correctly identifies OCSP as the operational validation mechanism expected on the exam.

Official Reference

Exam Strategy

Master the distinct responsibilities within PKI ecosystems by mapping each component to its exact function. Whenever a SY0-701 question mentions real-time validation, revocation checking, or verifying a certificate during a session, immediately discard the CA and select the protocol (OCSP) or list (CRL) mechanism.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide