A Certificate Revocation List (CRL) is a digitally signed list maintained by a Certificate Authority (CA) that contains revoked or expired certificates. This prevents clients from trusting compromised or outdated certificates. TPM (A) is a hardware security module, unrelated to certificate revocation. PKI (C) is the overall system managing digital certificates, but it does not store revocation lists. CSR (D) is a request to obtain a certificate, not to revoke one. Reference: CompTIA Security+ SY0-701 Official Study Guide, Security Architecture domain.