pki Flashcards
- Question: What is the primary function of a digital certificate in PKI?
a) Securely store private keys
b) Verify the authenticity of a public key
c) Encrypt email messages
d) Manage user passwords
Answer: b) Verify the authenticity of a public key
- Question: In PKI, what is the term for the process of confirming the validity of a certificate before accepting it for use?
a) Certificate issuance
b) Certificate revocation
c) Certificate validation
d) Certificate encryption
Answer: c) Certificate validation
- Question: Which component in PKI is responsible for digitally signing certificates?
a) Registration Authority (RA)
b) Certificate Revocation List (CRL)
c) Certification Authority (CA)
d) Public Key Infrastructure (PKI)
Answer: c) Certification Authority (CA)
- Question: What is the purpose of the Certificate Revocation List (CRL) in PKI?
a) To list all certificate holders
b) To authenticate users
c) To verify digital signatures
d) To identify revoked certificates
Answer: d) To identify revoked certificates
Answer: d) To identify revoked certificates
- Question: Which cryptographic algorithm is commonly used for digital signatures in PKI?
a) RSA
b) DES
c) MD5
d) HMAC
Answer: a) RSA
- Question: What does a digital signature provide in PKI?
a) Confidentiality
b) Integrity
c) Authentication
d) Availability
Answer: b) Integrity
- Question: Which protocol is often used for secure email communication in PKI?
a) HTTP
b) SMTP
c) POP3
d) FTP
Answer: b) SMTP
- Question: In a PKI, what is the purpose of the Public Key?
a) Encrypt messages
b) Verify signatures
c) Decrypt messages
d) Store passwords
Answer: b) Verify signatures
- Question: Which key is typically kept secret in a PKI key pair?
a) Public Key
b) Private Key
c) Session Key
d) Master Key
Answer: b) Private Key
- Question: Which entity is responsible for managing the issuance and revocation of digital certificates in a hierarchical PKI?
*a) End-users
b) Root CA
c) Registration Authority (RA)
d) Web browsers**
b) Root CA
- Question: Which PKI component confirms the identity of certificate applicants?
a) Public Key
b) Registration Authority (RA)
c) Certificate Revocation List (CRL)
d) Encryption Algorithm
b) Registration Authority (RA)
- Question: Which certificate format is commonly used for securing email communication in PKI?
a) X.509
b) PKCS#7
c) PEM
d) PGP
Answer: a) X.509
- Question: What does the term “Chain of Trust” refer to in PKI?
a) A series of CA certificates
b) A secure VPN connection
c) The process of encryption
d) A type of digital signature
a) A series of CA certificates
- Question: What is the purpose of the Key Escrow in PKI?
a) To store public keys
b) To recover lost private keys
c) To authenticate users
d) To issue digital certificates
b) To recover lost private keys
- Question: Which PKI component verifies the identity of users or entities before issuing a certificate?
a) Certificate Authority (CA)
b) Public Key
c) Registration Authority (RA)
d) Key Management System (KMS)
Answer: c) Registration Authority (RA)
- Question: Which cryptographic hash function is considered insecure and should be avoided in PKI?
a) SHA-256
b) MD5
c) SHA-1
d) HMAC-SHA-512
b) MD5
- Question: In PKI, what is the purpose of the Online Certificate Status Protocol (OCSP)?
a) To encrypt email messages
b) To issue digital certificates
c) To verify the revocation status of a certificate
d) To manage encryption keys
c) To verify the revocation status of a certificate
- Question: Which type of key is used to establish secure communication in PKI?
a) Public Key
b) Private Key
c) Shared Key
d) Secret Key
a) Public Key
- Question: What is the purpose of a Hardware Security Module (HSM) in PKI?
a) To issue digital certificates
b) To store private keys securely
c) To encrypt email messages
d) To validate digital signatures
b) To store private keys securely
- Question: Which PKI component is responsible for creating and managing digital certificates for users and devices?
a) Certificate Revocation List (CRL)
b) Registration Authority (RA)
c) Certification Authority (CA)
d) Public Key
c) Certification Authority (CA)