What Must Be Updated After a Stolen Website Private Key?

The private key for a website was stolen, and a new certificate has been issued. Which of the following needs to be updated next?

  1. SCEP
  2. CRL Source Reference Answer
  3. OCSP
  4. CSR

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests understanding of PKI revocation workflows, with the common trap being confusion between enrollment mechanisms (CSR/SCEP) and revocation infrastructure (CRL/OCSP).

When a website's private key is compromised, the associated digital certificate must be revoked to prevent unauthorized access or impersonation. The community overwhelmingly agrees that updating the Certificate Revocation List (CRL) is the critical next step to ensure clients and browsers reject the compromised certificate.

Candidates frequently select CSR (Certificate Signing Request), mistakenly believing that generating a new request is the immediate administrative action after a breach. However, a CSR is used to create a new certificate, not to invalidate the compromised one, making CRL the correct operational priority.

Community Discussion (6 comments)

4617f0b 👍 7 Selected: B
When a private key for a website is stolen, the certificate associated with that key is considered compromised. The next important step is to update the Certificate Revocation List (CRL) to include the old certificate so that clients and browsers know that it should no longer be trusted.
9149f41 👍 1 Selected: B
A. SCEP (Simple Certificate Enrollment Protocol)-for enrolling only C. OCSP (Online Certificate Status Protocol): check status online D. CSR (Certificate Signing Request): Request new certificate.
Anyio 👍 2 Selected: B
The correct answer is: B. CRL Explanation: When a private key is stolen, the associated certificate must be revoked to ensure it is no longer trusted. Updating the Certificate Revocation List (CRL) is necessary to inform systems that the certificate is invalid and should not be trusted. Other Options: A. SCEP (Simple Certificate Enrollment Protocol): Used for certificate enrollment but is not related to revoking or updating certificates. C. OCSP (Online Certificate Status Protocol): This protocol is used to check the revocation status of a certificate in real time, but the CRL must be updated first for OCSP to reflect the change. D. CSR (Certificate Signing Request): This is used to request a new certificate but does not handle revocation or updates related to the stolen private key.
ProudFather 👍 1 Selected: B
A Certificate Revocation List (CRL) is a list of digital certificates that have been revoked. When a private key is compromised, the corresponding certificate should be revoked to prevent its further use. By updating the CRL, the system can validate the authenticity of certificates and prevent unauthorized access.
Cocopqr 👍 1 Selected: D
D. CSR (Certificate Signing Request). Explanation: When a private key is compromised, the entire certificate needs to be reissued. This involves the following steps: Generate a new CSR: A new Certificate Signing Request (CSR) is generated, which includes the public key associated with the new private key. Submit the CSR to the CA: The new CSR is submitted to the Certificate Authority (CA) for verification and signing. Issue a new certificate: The CA issues a new digital certificate that is bound to the new public key. Once the new certificate is issued, it needs to be installed on the web server. The other options (SCEP, CRL, and OCSP) are related to certificate management and revocation, but they are not directly affected by the compromise of the private key and the issuance of a new certificate.
s_plus 👍 1
Simple Certificate Enrollment Protocol *Certificate Revocation List Offensive Security Certified Professional Certificate Signing Request

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Correct Answer Explanation

When a website's private key is stolen, the corresponding public key/certificate pair is considered compromised. Even if a new certificate has already been issued, systems must actively reject the old certificate to prevent attackers from impersonating the site or decrypting traffic. This is achieved through certificate revocation. Updating the Certificate Revocation List (CRL) ensures that all relying parties (browsers, operating systems, servers) receive an authoritative list marking the compromised certificate as invalid before its natural expiration date. As noted by multiple candidates in the community, this step is non-negotiable in security operations and incident response workflows involving PKI breaches.

While a new certificate is already issued in the scenario, the immediate administrative requirement is to publish the revocation status. The CRL acts as a centralized database of revoked certificates managed by the Certificate Authority (CA). Once updated, clients can check this list during TLS handshakes to block trust in the stolen certificate.

Why Other Options Are Incorrect

  • SCEP (Simple Certificate Enrollment Protocol) is an automated protocol for requesting and issuing certificates, not for revoking them. It plays no role in handling compromised keys.
  • OCSP (Online Certificate Status Protocol) is an alternative to CRLs for checking revocation status in real-time. While related to revocation, the question specifically asks what needs to be updated next. OCSP relies on responder data that is fundamentally derived from CA databases/CRL updates; the foundational update happens at the CRL level first.
  • CSR (Certificate Signing Request) is generated before a new certificate is issued to submit to a CA. Since the prompt states a new certificate has already been issued, generating a CSR is redundant and backwards in the workflow.

Community Insights & Exam Context

The SY0-701 exam frequently tests PKI lifecycle management. Candidates consistently emphasize that revocation takes precedence over reissuance in security operations. As highlighted in community discussions, confusing enrollment tools (SCEP, CSR) with revocation mechanisms (CRL, OCSP) is a classic distractor pattern. Mastering the distinction between certificate creation, validation, and revocation will solidify your approach to cryptography questions.

Official Reference

Exam Strategy

Focus on the sequence of the PKI lifecycle: issuance, renewal, and revocation. When a question involves a compromised credential, immediately eliminate enrollment-related options (CSR, SCEP) and prioritize revocation mechanisms (CRL, OCSP) as the primary mitigation step.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide