Certified Ethical Hacker (CEH) Practice Question

During a web application penetration test you capture a TLS 1.2 handshake in Wireshark. Immediately after the server's Certificate message you notice an optional CertificateStatus message that carries a signed OCSP response. From a PKI standpoint, what key benefit is the web server gaining by including this message (OCSP stapling) in the handshake?

  • It eliminates the need to transmit intermediate CA certificates, thereby shortening the TLS handshake.

  • It prevents man-in-the-middle attacks by encrypting the certificate with the server's private key before transmission.

  • It lowers client latency and preserves user privacy by removing the need for clients to query the certificate authority for revocation status.

  • It provides perfect forward secrecy by embedding the server's ephemeral Diffie-Hellman parameters in the certificate.

Certified Ethical Hacker (CEH)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot