COMPTIA SECURITY+ (SY0-601) 2026-2027 EXAM PAPER- REVISION QUESTIONS
& SOLUTIONS
General Data Protection Regulation (GDPR)
A regulation in EU law on data protection and privacy in the European Union and the European
Economic Area.
Asymmetric Encryption
A type of cryptographic based on algorithms that use a private and public key.
Certificate Authority (CA)
A server that manages digital certificates.
Public Key Infrastructure (PKI)
A system for managing digital certificates and public key encryption.
Online Certificate Authority
An internal online certificate authority.
Offline Certificate Authority
An internal offline certificate authority.
Public Certificate Authority
Third-party that manages digital certificates.
Certificate Revocation List (CRL)
A list that keeps of track of whether a digital certificate is valid.
Private Certificate Authority
An internal digital certificate management system.
Registration Authority (RA)
Validates and accepts requests for certificates.
X.509 Certificate
A standard defining the format of public key certificates.
,Root Certificate Authority/Trust Anchor
The root certificate from which the whole chain of trust is derived.
Subordinate Certificate Authority/Intermediary
Defines and authorises the types of certificates that can be requested from the Root Certificate
Authority.
Certificate Pinning
Prevents the compromise of Certificate Authorities and fraudulent certificate issuing.
Trust Model
Provides authenticity of a certificate.
Hierarchical Trust Model
A trust model that has a single hierarchy with one master certificate authority.
Bridge Trust Model
A trust model with one certificate authority that acts as a facilitator to interconnect all other
certificate authorities.
Certificate Chaining
Linking several certificates together to establish trust between all the certificates involved.
Online Certificate Status Protocol (OCSP)
A protocol that performs a real-time lookup of a certificate's status.
OSCP Stapling/Certificate Stapling
When a web server bypasses the certificate revocation list to use OSCP.
Certificate Signing Request (CSR)
The process of requesting a new certificate.
Hard Security Module (HSM)
A physical computing device that safeguards and manages digital keys
Key Escrow
A store for holding private keys for their parties that are stored a Hardware Security Module.
Data Recovery Agent (DRA)
,A user account that an administrator has authorized to recover BitLocker drives for an entire
organization with a digital certificate on a smart card.
Public Key
An asymmetric encryption key that encrypts data, uses a P7B format with a .cer file extension.
Private Key
An asymmetric encryption key that decrypts data and uses the P12 format with a .pfx file
extension.
Object Identifier (OID)
A designator made up of a series of numbers separated with a dot which names an object or
entity.
Privacy Enhanced Mail Certificate (PEM)
A digital certificate that uses a Bas64 format, with a .pem file extension.
Distinguished Encoding Rules Certificate (DER)
A digital certificate that uses a Base64 format with the .der file extension.
Self-Signed Certificate
A certificate that is issued by the same entity that is using it and doesn't have a certificate
revocation list.
Wildcard Certificate
A PKI certificate that is applied to a specific domain but also covers all of the subdomains.
Fully Qualified Domain Name (FQDN)
The complete domain name of an Internet computer.
Domain-Validated Certificate (DV)
A certificate that proves the ownership of a domain name.
Subject Alternative Name (SAN)
A certificate with that allows for use on multiple domains.
Code Signing
, The process of assigning a certificate to code. The certificate includes a digital signature and
validates the code.
Computer/Machine Certificate
A certificate that identifies a computer within a domain.
User Certificate
A certificate that authenticates a user.
Extended Validation Certificate
Increased security over domain validation certificates due to an enhanced validation process,
which requires human validation.
Substitution/Caesar Cipher
Monoalphabetic cipher that shifts characters.
Rotate 13 (ROT 13)
Monoalphabetic cipher that shifts characters 13 characters.
Symmetric Encryption
An encryption method whereby the same key is used to encode and to decode the data.
Data Encryption Standard (DES)
A symmetric block cipher that uses a 56-bit key and encrypts data in 64-bit blocks.
Triple Data Encryption Standard (3DES)
A symmetric block cipher similar to DES but uses a key that can be three times the size, at a 168-
bit key.
Advanced Encryption Standard (AES)
A symmetric block cipher created in the late 1990s that uses a 128-bit block size and a 128-,
192-, or 256-bit key size.
Twofish
A symmetric block cipher that operates on 128-bit blocks of data and is capable of using
cryptographic keys up to 256 bits in length.
Blowfish
& SOLUTIONS
General Data Protection Regulation (GDPR)
A regulation in EU law on data protection and privacy in the European Union and the European
Economic Area.
Asymmetric Encryption
A type of cryptographic based on algorithms that use a private and public key.
Certificate Authority (CA)
A server that manages digital certificates.
Public Key Infrastructure (PKI)
A system for managing digital certificates and public key encryption.
Online Certificate Authority
An internal online certificate authority.
Offline Certificate Authority
An internal offline certificate authority.
Public Certificate Authority
Third-party that manages digital certificates.
Certificate Revocation List (CRL)
A list that keeps of track of whether a digital certificate is valid.
Private Certificate Authority
An internal digital certificate management system.
Registration Authority (RA)
Validates and accepts requests for certificates.
X.509 Certificate
A standard defining the format of public key certificates.
,Root Certificate Authority/Trust Anchor
The root certificate from which the whole chain of trust is derived.
Subordinate Certificate Authority/Intermediary
Defines and authorises the types of certificates that can be requested from the Root Certificate
Authority.
Certificate Pinning
Prevents the compromise of Certificate Authorities and fraudulent certificate issuing.
Trust Model
Provides authenticity of a certificate.
Hierarchical Trust Model
A trust model that has a single hierarchy with one master certificate authority.
Bridge Trust Model
A trust model with one certificate authority that acts as a facilitator to interconnect all other
certificate authorities.
Certificate Chaining
Linking several certificates together to establish trust between all the certificates involved.
Online Certificate Status Protocol (OCSP)
A protocol that performs a real-time lookup of a certificate's status.
OSCP Stapling/Certificate Stapling
When a web server bypasses the certificate revocation list to use OSCP.
Certificate Signing Request (CSR)
The process of requesting a new certificate.
Hard Security Module (HSM)
A physical computing device that safeguards and manages digital keys
Key Escrow
A store for holding private keys for their parties that are stored a Hardware Security Module.
Data Recovery Agent (DRA)
,A user account that an administrator has authorized to recover BitLocker drives for an entire
organization with a digital certificate on a smart card.
Public Key
An asymmetric encryption key that encrypts data, uses a P7B format with a .cer file extension.
Private Key
An asymmetric encryption key that decrypts data and uses the P12 format with a .pfx file
extension.
Object Identifier (OID)
A designator made up of a series of numbers separated with a dot which names an object or
entity.
Privacy Enhanced Mail Certificate (PEM)
A digital certificate that uses a Bas64 format, with a .pem file extension.
Distinguished Encoding Rules Certificate (DER)
A digital certificate that uses a Base64 format with the .der file extension.
Self-Signed Certificate
A certificate that is issued by the same entity that is using it and doesn't have a certificate
revocation list.
Wildcard Certificate
A PKI certificate that is applied to a specific domain but also covers all of the subdomains.
Fully Qualified Domain Name (FQDN)
The complete domain name of an Internet computer.
Domain-Validated Certificate (DV)
A certificate that proves the ownership of a domain name.
Subject Alternative Name (SAN)
A certificate with that allows for use on multiple domains.
Code Signing
, The process of assigning a certificate to code. The certificate includes a digital signature and
validates the code.
Computer/Machine Certificate
A certificate that identifies a computer within a domain.
User Certificate
A certificate that authenticates a user.
Extended Validation Certificate
Increased security over domain validation certificates due to an enhanced validation process,
which requires human validation.
Substitution/Caesar Cipher
Monoalphabetic cipher that shifts characters.
Rotate 13 (ROT 13)
Monoalphabetic cipher that shifts characters 13 characters.
Symmetric Encryption
An encryption method whereby the same key is used to encode and to decode the data.
Data Encryption Standard (DES)
A symmetric block cipher that uses a 56-bit key and encrypts data in 64-bit blocks.
Triple Data Encryption Standard (3DES)
A symmetric block cipher similar to DES but uses a key that can be three times the size, at a 168-
bit key.
Advanced Encryption Standard (AES)
A symmetric block cipher created in the late 1990s that uses a 128-bit block size and a 128-,
192-, or 256-bit key size.
Twofish
A symmetric block cipher that operates on 128-bit blocks of data and is capable of using
cryptographic keys up to 256 bits in length.
Blowfish