A security team is implementing a PKI for a large enterprise. Which TWO of the following are commonly used methods for certificate revocation checking? (Select TWO.)
OCSP queries a responder for the real-time revocation status of a specific certificate, returning good, revoked or unknown. This satisfies the enterprise PKI requirement for a commonly used revocation checking method, offering lower latency than downloading a full list.
Why this answer
Option B, Online Certificate Status Protocol (OCSP), is correct because it is a standard protocol defined in RFC 6960 that allows a client to query a dedicated OCSP responder in real time to determine whether a specific certificate has been revoked, returning a status of good, revoked, or unknown. Option C, Certificate Revocation List (CRL), is correct because it is a signed list published by the Certificate Authority (typically distributed via HTTP, LDAP, or FTP at the CDP extension URL) that enumerates the serial numbers of certificates that have been revoked before their expiration date. The remaining options are not revocation-checking methods: a Certificate Signing Request (A) is a message sent to a CA to request issuance of a certificate, Key Escrow (D) is the practice of storing private keys with a third party for recovery purposes, and the Digital Signature Algorithm (E) is a signing algorithm used to create and verify digital signatures, not to check revocation status.
Exam trap
The trap is confusing certificate lifecycle elements like CSR or key escrow with revocation checking mechanisms, or picking cryptographic algorithms like DSA that are unrelated to revocation.