CompTIA Security+ (SY0-701)General Security ConceptsHard
An organization is deploying a public key infrastructure and wants a dedicated component to verify the identity of certificate requesters by checking government-issued identification and organizational documents before forwarding approved requests to the certificate authority for signing. Which PKI component should perform this identity verification role?
- ACertificate Revocation List
- BKey Escrow Agent
- CRegistration Authority
- DOnline Certificate Status Protocol responder
Show answer & explanationAnswer & explanation
Correct answer: C. Registration Authority
The Registration Authority (RA) acts as the intermediary that verifies the identity of a certificate requester before forwarding the validated request to the CA for signing, offloading the identity-vetting workload from the CA itself. The CRL and OCSP responder handle revocation status, not identity verification, and a key escrow agent stores private keys, not identity documents.
Why the other options are wrong
- A. A CRL is a published list of revoked certificates, unrelated to vetting new requesters.
- B. Key escrow securely stores copies of private keys, not identity verification.
- D. OCSP provides real-time revocation status, not identity vetting for new certificate requests.
Registration Authority (RA)
A PKI component that verifies the identity of certificate requesters and forwards validated requests to the Certificate Authority for signing.
- Offloads identity vetting from the CA.
- Does not itself issue or sign certificates.
- Reduces CA workload and improves scalability of certificate issuance.
Memory trick: RA checks your ID, CA signs your certificate