Infrastructure (PKI) Test Exam Questions
(Actual Exam 2026-2027) Correct
Detailed & Verified ANSWERS (100%
Accurate Solutions) ALREADY
GRADED A+||NEWEST VERSION Of
The Exam Guarantee Pass!!
1. What is the primary purpose of Public Key Infrastructure (PKI)?
A. Managing network bandwidth
B. Encrypting all database transactions
C. Providing digital identity verification and secure key management
D. Preventing malware infections
PKI provides a framework for managing digital certificates, public/private keys,
authentication, and trust relationships.
2. Which key is kept secret in an asymmetric encryption system?
A. Public key
B. Certificate authority key
C. Session key
D. Private key
The private key must remain confidential because it is used for decryption and digital
signatures.
3. Which organization issues digital certificates?
A. Firewall
B. IDS
C. Certificate Authority (CA)
D. Proxy server
A Certificate Authority validates identities and issues trusted digital certificates.
,4. What does a digital certificate primarily provide?
A. Faster encryption
B. Association between an identity and a public key
C. Malware detection
D. Network segmentation
Digital certificates bind a public key to an entity such as a person, server, or organization.
5. Which PKI component validates certificate requests?
A. Router
B. CRL
C. Registration Authority (RA)
D. HSM
The Registration Authority verifies the identity of certificate applicants before certificates are
issued.
6. What does a Certificate Revocation List (CRL) contain?
A. Encryption algorithms
B. User passwords
C. Certificates that are no longer trusted
D. Public keys only
A CRL identifies certificates that have been revoked before their expiration date.
7. Which protocol is commonly used to check whether a certificate has been
revoked in real time?
A. FTP
B. OCSP
C. SMTP
D. SNMP
Online Certificate Status Protocol (OCSP) provides real-time certificate validity checking.
8. Which type of encryption uses a public and private key pair?
, A. Symmetric encryption
B. Hashing
C. Asymmetric encryption
D. Steganography
Asymmetric encryption relies on mathematically related public and private keys.
9. A user signs a document using their private key. What does this provide?
A. Confidentiality
B. Availability
C. Non-repudiation and authenticity
D. Compression
Digital signatures prove who signed the data and ensure the signer cannot easily deny it.
10. Which PKI component stores and protects private keys?
A. DNS server
B. Hardware Security Module (HSM)
C. Switch
D. Load balancer
HSMs provide secure storage and cryptographic operations for sensitive keys.
11. What is the main purpose of a root CA?
A. Issue user passwords
B. Monitor network traffic
C. Establish the highest level of trust in a PKI hierarchy
D. Encrypt email messages
The root CA is the trust anchor from which subordinate certificates derive trust.
12. A certificate signed by an unknown CA will most likely result in:
A. Faster authentication
B. A trust warning from the browser or operating system
C. Increased encryption strength
D. Automatic approval