Pre-Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ac4s65

An administrator is designing a public key infrastructure (PKI) integration for a large-scale deployment with...

An administrator is designing a public key infrastructure (PKI) integration for a large-scale deployment with thousands of users authenticating via client certificates. A key design goal is to ensure that certificate revocation status is checked efficiently with minimal impact on firewall performance and minimal delay for the connecting user.

What is the primary advantage of using the Online Certificate Status Protocol (OCSP) instead of certificate revocation lists (CRLs) in this scenario?

A.

OCSP allows the firewall to act as its own certificate authority (CA), and it simplifies certificate management.

B.

OCSP provides real-time status for a certificate on demand, is more scalable, and uses less firewall memory.

C.

OCSP is an older, more widely supported protocol than CRLs. ensuring compatibility with all client devices.

D.

OCSP bundles all certificate statuses into a single, digitally signed file for faster downloads by the firewall.

NGFW-Engineer PDF/Engine
  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions
buy now NGFW-Engineer pdf
Get 65% Discount on All Products, Use Coupon: "ac4s65"