Introduction to Cryptography - D334
ACTUAL EXAM 2026 Questions and
Answers
An entity looking to obtain a digital certificate must first generate ____.
a symmetric key
an asymmetric key pair
a registration authority
a certificate authority - Correct answer-an asymmetric key pair
-Someone looking to obtain a digital certificate will first generate an asymmetric
key pair and then generate a certificate signing request (CSR). The person will
provide the CA with the public key from the generated key pair along with the
CSR to formally request a digital certificate.
4 Basic steps for obtaining a digital certificate signed by a trusted Certificate
Authority (CA):
Step 1: Requester generates a keypair (one public, one private).
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,Step 2: Requester creates a Certificate Signing Request (CSR) and submits CSR
(which includes public key from the key pair generated) to the CA.
Step 3: CA validates submission and generates the digital certificate for the
requester.
Step 4: CA signs the requester's digital certificate with the CA's own private key
and issues certificate to the requester.
Which encoding scheme for X.509 certificates supports Base64 and ASCII text
formats?
DER
CSR
IKE
PEM - Correct answer-PEM
- Two major encoding schemes for X.509 certificates: PEM (Base64, ASCII text)
format, and DER (binary) format.
A ___ validates the unique identifying information and public key information
submitted by a requester and creates a digital certificate which essentially binds the
requester's identity and public key to the certificate.
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
, CSR
RA
CA
CRL - Correct answer-CA
- When a requester sends a CSR to a CA in a secure, verifiable way, upon receipt,
the CA will: verify the requester is who they say they are and that they actually
sent the message, verify the public key is the requester's key and is the match to the
requester's private key, and verify the identity information provided in the CSR is
correct before creating the digital certificate for the requester
The timeframe a digital certificate is considered to be valid and can be trusted, is
known as the _____.
CRL
CSR
cancelation stage
period of validity - Correct answer-period of validity
- Certificates receive a period of validity designation (timeframe the cert is valid
and should be trusted) at creation via a start and end date or expiration date. A
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3
ACTUAL EXAM 2026 Questions and
Answers
An entity looking to obtain a digital certificate must first generate ____.
a symmetric key
an asymmetric key pair
a registration authority
a certificate authority - Correct answer-an asymmetric key pair
-Someone looking to obtain a digital certificate will first generate an asymmetric
key pair and then generate a certificate signing request (CSR). The person will
provide the CA with the public key from the generated key pair along with the
CSR to formally request a digital certificate.
4 Basic steps for obtaining a digital certificate signed by a trusted Certificate
Authority (CA):
Step 1: Requester generates a keypair (one public, one private).
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,Step 2: Requester creates a Certificate Signing Request (CSR) and submits CSR
(which includes public key from the key pair generated) to the CA.
Step 3: CA validates submission and generates the digital certificate for the
requester.
Step 4: CA signs the requester's digital certificate with the CA's own private key
and issues certificate to the requester.
Which encoding scheme for X.509 certificates supports Base64 and ASCII text
formats?
DER
CSR
IKE
PEM - Correct answer-PEM
- Two major encoding schemes for X.509 certificates: PEM (Base64, ASCII text)
format, and DER (binary) format.
A ___ validates the unique identifying information and public key information
submitted by a requester and creates a digital certificate which essentially binds the
requester's identity and public key to the certificate.
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
, CSR
RA
CA
CRL - Correct answer-CA
- When a requester sends a CSR to a CA in a secure, verifiable way, upon receipt,
the CA will: verify the requester is who they say they are and that they actually
sent the message, verify the public key is the requester's key and is the match to the
requester's private key, and verify the identity information provided in the CSR is
correct before creating the digital certificate for the requester
The timeframe a digital certificate is considered to be valid and can be trusted, is
known as the _____.
CRL
CSR
cancelation stage
period of validity - Correct answer-period of validity
- Certificates receive a period of validity designation (timeframe the cert is valid
and should be trusted) at creation via a start and end date or expiration date. A
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3