If my memory serves me well, PKI (public key infrastructure) is a set of roles needed to manage digital certificates and public-key encryption. AD CS (active directory certificate services) is a tool that helps to manage public-key certificates. So the answer is: Status Protocol (OCSP) is used to validate certificates.