Courseiva
Cryptography →mediumMultiple Choice

SSCP Cryptography Practice Question

A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?

⚠ Common exam trap

Candidates often confuse the CRL's purpose with certificate validation or storage, mistakenly thinking it validates chains or stores all certificates, when in fact it only publishes revoked certificates for status checking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To publish revoked certificates

The primary purpose of a Certificate Revocation List (CRL) is to publish a list of certificates that have been revoked by the Certificate Authority (CA) before their scheduled expiration. This allows relying parties to verify that a certificate is still valid and has not been compromised, ensuring trust in the PKI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To validate certificate chains

    Why it's wrong here

    Chain validation is performed by verifying signatures up to a trusted root, using issuer and subject fields, not by consulting a CRL. It is tempting because CRLs are consumed during path validation as a status check, and a CRL would be the correct mechanism when the specific requirement is determining whether a certificate has been revoked rather than whether its signatures chain correctly.

  • ✗

    To encrypt certificate requests

    Why it's wrong here

    CRLs are signed lists of revoked serial numbers; they never encrypt certificate requests, which are protected by the requester's own key or transport security. It is tempting because CRLs are cryptographic objects distributed by the CA, and a CRL would be the right answer when the question asks how revocation status is published rather than how enrolment requests are protected.

  • ✗

    To store all issued certificates

    Why it's wrong here

    A CRL lists certificates that have been revoked before expiry; it does not store issued certificates, which live in the CA database or repository. It is tempting because both are certificate-related repositories maintained by the CA, and a CRL would be the right artefact when a relying party must check whether a previously trusted certificate has been invalidated.

  • ✓

    To publish revoked certificates

    Why this is correct

    A CRL is a signed, timestamped list issued by the certificate authority enumerating serial numbers of certificates revoked before their expiry. Validators check it during path validation so revoked certificates are rejected, satisfying the PKI requirement to publish revocation status.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.