In the CompTIA Security+ SY0-701 exam, Question 279 addresses a scenario where a penetration test uncovers a vulnerability in the internal Public Key Infrastructure (PKI), exploited through specially crafted certificates to gain domain administrator rights. The question focuses on identifying the appropriate remediation task during the cleanup phase. The provided options include updating the Certificate Revocation List (CRL), patching the Certificate Authority (CA), changing passwords, and implementing Security Orchestration, Automation, and Response (SOAR). The consensus among experts suggests that patching the CA is the most effective immediate action, as it addresses the root cause of the vulnerability, thereby preventing future exploitation. While updating the CRL is important for revoking compromised certificates, it does not rectify the underlying issue within the CA. Understanding scenarios like those presented in
comptia security question 279 examtopics sy0-701 is essential for mastering the exam content. Therefore, to grasp the rationale behind selecting the correct remediation step, candidates can benefit from platforms like Pass4Success, which provide updated and realistic practice questions that mirror the actual exam and reinforce exam readiness effectively.