SSCP Cryptography Practice Question
A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?
⚠ Common exam trap
Candidates often confuse the CRL's purpose with certificate validation or storage, mistakenly thinking it validates chains or stores all certificates, when in fact it only publishes revoked certificates for status checking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To publish revoked certificates
The primary purpose of a Certificate Revocation List (CRL) is to publish a list of certificates that have been revoked by the Certificate Authority (CA) before their scheduled expiration. This allows relying parties to verify that a certificate is still valid and has not been compromised, ensuring trust in the PKI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To validate certificate chains
Why it's wrong here
Chain validation is performed by verifying signatures up to a trusted root, using issuer and subject fields, not by consulting a CRL. It is tempting because CRLs are consumed during path validation as a status check, and a CRL would be the correct mechanism when the specific requirement is determining whether a certificate has been revoked rather than whether its signatures chain correctly.
- ✗
To encrypt certificate requests
Why it's wrong here
CRLs are signed lists of revoked serial numbers; they never encrypt certificate requests, which are protected by the requester's own key or transport security. It is tempting because CRLs are cryptographic objects distributed by the CA, and a CRL would be the right answer when the question asks how revocation status is published rather than how enrolment requests are protected.
- ✗
To store all issued certificates
Why it's wrong here
A CRL lists certificates that have been revoked before expiry; it does not store issued certificates, which live in the CA database or repository. It is tempting because both are certificate-related repositories maintained by the CA, and a CRL would be the right artefact when a relying party must check whether a previously trusted certificate has been invalidated.
- ✓
To publish revoked certificates
Why this is correct
A CRL is a signed, timestamped list issued by the certificate authority enumerating serial numbers of certificates revoked before their expiry. Validators check it during path validation so revoked certificates are rejected, satisfying the PKI requirement to publish revocation status.
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.