CAS-004 Security Engineering Practice Question
An incident response team discovers that an attacker was able to forge a certificate for a legitimate domain. Which TWO mechanisms should the team implement to detect and prevent such misissuance in the future? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate Transparency (CT) logging and monitoring
Certificate Transparency (CT) logging and monitoring (D) is correct because CT requires CAs to submit every issued certificate to public, append-only logs, so the team can monitor these logs for unauthorized or forged certificates for their domains and detect misissuance quickly. Certificate pinning in client applications (E) is correct because it hardcodes or constrains the expected certificate/public key for a domain, so a forged certificate issued by a rogue or compromised CA will be rejected by the client, preventing its use even if it chains to a trusted root. CRLs (A) and OCSP stapling (C) only convey revocation status of certificates and cannot detect or prevent a newly forged certificate that has not yet been revoked, and EV certificates (B) merely assert a higher validation level without providing any detection or pinning mechanism against misissuance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Certificate Revocation Lists (CRLs)
Why it's wrong here
CRLs list certificates a CA has already revoked, so they act after misissuance is discovered and depend on clients fetching large, stale lists. They would be correct for distributing revocation status of known-bad certificates, but they cannot detect a forged certificate or stop a CA from issuing one.
- ✗
Implementing Extended Validation (EV) certificates
Why it's wrong here
EV certificates only assert stronger identity vetting within the same CA trust model; they neither detect misissued certificates nor prevent a compromised or rogue CA from signing for a domain. EV would be the right selection when a site needs heightened organisational identity assurance, not for detecting or blocking misissuance.
- ✗
Online Certificate Status Protocol (OCSP) stapling
Why it's wrong here
OCSP stapling lets a server present a signed, timestamped revocation response, reducing client lookups, but it still only reports revocation status of an already-issued certificate. It would be the right choice for efficient revocation checking, not for detecting or preventing misissuance itself.
- ✓
Certificate Transparency (CT) logging and monitoring
Why this is correct
Certificate Transparency publishes every issued certificate to append-only, cryptographically verifiable logs, letting the team detect unauthorised or forged certificates for their domains. Monitoring these logs satisfies the misissuance detection requirement by exposing certificates the legitimate CA never intended to issue.
- ✓
Certificate pinning in client applications
Why this is correct
Certificate pinning hard-codes the expected public key or certificate into client applications, so a forged certificate from any CA fails validation. This satisfies the prevention requirement by removing reliance on the broader CA trust model for that specific domain.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.