CompTIA Security+ (SY0-701)General Security ConceptsHard

An organization is deploying a public key infrastructure and wants a dedicated component to verify the identity of certificate requesters by checking government-issued identification and organizational documents before forwarding approved requests to the certificate authority for signing. Which PKI component should perform this identity verification role?

  1. ACertificate Revocation List
  2. BKey Escrow Agent
  3. CRegistration Authority
  4. DOnline Certificate Status Protocol responder
Show answer & explanation

Correct answer: C. Registration Authority

The Registration Authority (RA) acts as the intermediary that verifies the identity of a certificate requester before forwarding the validated request to the CA for signing, offloading the identity-vetting workload from the CA itself. The CRL and OCSP responder handle revocation status, not identity verification, and a key escrow agent stores private keys, not identity documents.

Why the other options are wrong

  • A. A CRL is a published list of revoked certificates, unrelated to vetting new requesters.
  • B. Key escrow securely stores copies of private keys, not identity verification.
  • D. OCSP provides real-time revocation status, not identity vetting for new certificate requests.

Registration Authority (RA)

A PKI component that verifies the identity of certificate requesters and forwards validated requests to the Certificate Authority for signing.

  • Offloads identity vetting from the CA.
  • Does not itself issue or sign certificates.
  • Reduces CA workload and improves scalability of certificate issuance.

Memory trick: RA checks your ID, CA signs your certificate

More General Security Concepts questions