A security team is deploying a new internal TLS certificate authority (CA) for service-to-service authentication. The CA private key must be protected, and the team wants to ensure that if the key is compromised, the attacker cannot forge certificates without detection. Which of the following is the MOST effective control to detect unauthorized certificate issuance?
CT logs provide an append-only, publicly auditable record of issued certificates. Publishing internal certificates to a CT log allows the security team to monitor for unauthorized issuance; any forged certificate would appear in the log, enabling detection. This is the most effective detective control among the options, as it directly addresses the risk of undetected certificate forgery.
Why this answer
Certificate Transparency logs create a verifiable record of all certificates issued by a CA. By publishing internal certificates to a CT log, the team can monitor for unexpected entries, which would indicate unauthorized issuance. This detective control is more effective than preventive measures like key size or pinning, which do not alert on forgery.
Exam trap
The trap here is assuming that stronger cryptographic keys or client-side pinning will detect a compromised CA, when detection requires an auditable record such as Certificate Transparency.