What Must Be Updated After a Stolen Website Private Key?
The private key for a website was stolen, and a new certificate has been issued. Which of the following needs to be updated next?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests understanding of PKI revocation workflows, with the common trap being confusion between enrollment mechanisms (CSR/SCEP) and revocation infrastructure (CRL/OCSP).
When a website's private key is compromised, the associated digital certificate must be revoked to prevent unauthorized access or impersonation. The community overwhelmingly agrees that updating the Certificate Revocation List (CRL) is the critical next step to ensure clients and browsers reject the compromised certificate.
Candidates frequently select CSR (Certificate Signing Request), mistakenly believing that generating a new request is the immediate administrative action after a breach. However, a CSR is used to create a new certificate, not to invalidate the compromised one, making CRL the correct operational priority.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answer Explanation
When a website's private key is stolen, the corresponding public key/certificate pair is considered compromised. Even if a new certificate has already been issued, systems must actively reject the old certificate to prevent attackers from impersonating the site or decrypting traffic. This is achieved through certificate revocation. Updating the Certificate Revocation List (CRL) ensures that all relying parties (browsers, operating systems, servers) receive an authoritative list marking the compromised certificate as invalid before its natural expiration date. As noted by multiple candidates in the community, this step is non-negotiable in security operations and incident response workflows involving PKI breaches.While a new certificate is already issued in the scenario, the immediate administrative requirement is to publish the revocation status. The CRL acts as a centralized database of revoked certificates managed by the Certificate Authority (CA). Once updated, clients can check this list during TLS handshakes to block trust in the stolen certificate.
Why Other Options Are Incorrect
- SCEP (Simple Certificate Enrollment Protocol) is an automated protocol for requesting and issuing certificates, not for revoking them. It plays no role in handling compromised keys.
- OCSP (Online Certificate Status Protocol) is an alternative to CRLs for checking revocation status in real-time. While related to revocation, the question specifically asks what needs to be updated next. OCSP relies on responder data that is fundamentally derived from CA databases/CRL updates; the foundational update happens at the CRL level first.
- CSR (Certificate Signing Request) is generated before a new certificate is issued to submit to a CA. Since the prompt states a new certificate has already been issued, generating a CSR is redundant and backwards in the workflow.
Community Insights & Exam Context
The SY0-701 exam frequently tests PKI lifecycle management. Candidates consistently emphasize that revocation takes precedence over reissuance in security operations. As highlighted in community discussions, confusing enrollment tools (SCEP, CSR) with revocation mechanisms (CRL, OCSP) is a classic distractor pattern. Mastering the distinction between certificate creation, validation, and revocation will solidify your approach to cryptography questions.Official Reference
- https://www.rfc-editor.org/rfc/rfc5280
- https://csrc.nist.gov/publications/detail/sp/800-57/part-1/final
- CompTIA Security+ SY0-701 Official Study Guide - Cryptography & PKI Domain
Exam Strategy
Focus on the sequence of the PKI lifecycle: issuance, renewal, and revocation. When a question involves a compromised credential, immediately eliminate enrollment-related options (CSR, SCEP) and prioritize revocation mechanisms (CRL, OCSP) as the primary mitigation step.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →