SSCP Systems Security Certified PractitionerCryptographyEasy

A company is implementing a Public Key Infrastructure (PKI) to secure its internal communications. As part of this implementation, a server is designated to issue, revoke, and manage digital certificates. What role does this server fulfill within the PKI?

  1. ACertificate Authority (CA)
  2. BRegistration Authority (RA)
  3. CCertificate Repository (CR)
  4. DValidation Authority (VA)
Show answer & explanation

Correct answer: A. Certificate Authority (CA)

The Certificate Authority (CA) is the trusted entity responsible for issuing, revoking, and managing digital certificates within a PKI.

Why the other options are wrong

  • B. A Registration Authority (RA) verifies identities but does not issue certificates.
  • C. A Certificate Repository (CR) stores certificates and CRLs for public access, but does not issue or revoke them.
  • D. A Validation Authority (VA) specifically validates the status of certificates, often using CRLs or OCSP.

Certificate Authority (CA)

A trusted entity in a PKI that issues, revokes, and manages digital certificates.

  • Root of trust in a PKI.
  • Digitally signs certificates it issues.
  • Maintains Certificate Revocation Lists (CRLs).

Memory trick: PKI is like a government for digital identities, with different departments.

More Cryptography questions