Correct Answer: A well-governed internal or trusted external CA, hardware-backed private key storage where possible, automated certificate lifecycle management (issuance, renewal, revocation), and integration with access policy that verifies certificate validity at each access attempt
Explanation: A well-governed CA, hardware-backed key storage, automated lifecycle management, and per-access certificate validation together provide a secure, scalable deployment, unlike manual spreadsheet tracking, non-expiring non-revocable certificates, storing keys in a shared folder, validating only at initial issuance, or using one shared certificate for everyone.
Correct Answer: A well-governed internal or trusted external CA, hardware-backed private key storage where possible, automated certificate lifecycle management (issuance, renewal, revocation), and integration with access policy that verifies certificate validity at each access attempt
Explanation: A well-governed CA, hardware-backed key storage, automated lifecycle management, and per-access certificate validation together provide a secure, scalable deployment, unlike manual spreadsheet tracking, non-expiring non-revocable certificates, storing keys in a shared folder, validating only at initial issuance, or using one shared certificate for everyone.