Valid CAS-005 Dumps shared by EduDump.com for Helping Passing CAS-005 Exam! EduDump.com now offer the newest CAS-005 exam dumps, the EduDump.com CAS-005 exam questions have been updated and answers have been corrected get the newest EduDump.com CAS-005 dumps with Test Engine here:
A security engineer is implementing a code signing requirement for all code developed by the organization. Currently, the PKI only generates website certificates. Which of the following steps should the engineer perform first?
Correct Answer: A
To enable code signing with an existing PKI, the first step is to configure the Certificate Authority (CA) to issue code signing certificates. Adding a new template with attributes specific to code signing (e.g., key usage for signing) allows the CA to support this requirement without disrupting existing operations. Option A:Correct-templates define certificate types; this isthe foundational step. Option B:Wildcard certificates are for domains, not code signing. Option C:Recalculating root CA keys is unnecessary and risky unless compromised. Option D:SAN (Subject Alternative Name) is for multi-domain certificates, irrelevant here. Reference:CompTIA SecurityX CAS-005 Domain 2: Security Architecture - PKI Implementation.