ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your team is integrating a cloud-based IRM platform that issues user-specific X.509 certificates to protect downloaded documents. Corporate policy states that if an employee account is disabled, the user must be blocked from opening any previously obtained protected files within five minutes, without imposing heavy, periodic downloads on all clients. Which certificate status-checking method best meets this requirement?
Query an OCSP responder for real-time validation each time a protected document is opened.
Issue certificates that expire every 24 hours and rely on their natural expiration for revocation.
Distribute an hourly delta Certificate Revocation List (CRL) that clients must download before access.
Rely on a weekly Authority Revocation List (ARL) published by the root Certificate Authority.
The Online Certificate Status Protocol (OCSP) allows clients to query a trusted responder each time a protected document is opened and receive an immediate, lightweight response about the certificate's revocation state. Because the check occurs in near real time and only the status of the single certificate is returned, OCSP both satisfies the five-minute revocation requirement and minimizes bandwidth.
Downloading a full CRL on a fixed schedule (even hourly delta CRLs) can still leave a gap up to the next distribution interval and consumes more bandwidth. Relying on short certificate validity periods offers no means to revoke a certificate before expiry, leaving an unacceptable window. Authority Revocation Lists are intended to revoke CA certificates, not end-entity certificates, so they do not meet the stated need.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is OCSP and how does it work?
Open an interactive chat with Bash
How does OCSP differ from CRLs?
Open an interactive chat with Bash
What are the advantages of using OCSP for certificate validation?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .