WorksheetsLevel 5 - Certificates & PKI Quiz
Total questions: 13
Worksheet time: 7mins
What is the primary role of asymmetric cryptography in PKI?
Providing confidentiality and trust
Issuing certificates to organizations
Managing certificate revocation lists (CRLs)
Creating a hierarchy of multiple CAs
What is the purpose of the Online Certificate Status Protocol (OCSP) in PKI?
Issuing digital certificates
Managing certificate attributes
Determining the validity of certificates in real-time
Creating a hierarchy of CAs
Which entity is responsible for validating and distributing certificates in a PKI?
Registration Authority (RA)
Intermediate CA
Issuing CA
Root CA
What information does a Certificate Signing Request (CSR) include?
Serial number and signature algorithm
Public key and OCSP responder details
Common name and organization details
Private key and certificate attributes
What is the primary purpose of a Wildcard Certificate?
Covering multiple domains with one certificate
Proving the legitimacy of an application
Validating an organization's legal existence
Identifying and validating specific users or computers
Which certificate type is used to prove that an application is legitimate?
Root Certificate
Code Signing Certificate
Wildcard Certificate
Subject Alternative Name (SAN)
What is a characteristic of Self-Signed Certificates?
Issued by Certificate Authorities (CAs)
Used for secure, encrypted emails
Requires thorough organization validation
Do not provide the same protection and security as CA-validated certificates
Which SSL validation level requires the purchaser to prove domain administration and undergo a thorough identity verification process?
Domain Validation
Organization Validation
Extended Validation
Subject Alternative Name (SAN) Validation
What is the primary purpose of certificate chaining or the Chain of Trust in a PKI hierarchy?
To increase the number of CAs in the hierarchy
To protect the root CA from compromise
To simplify the process of certificate issuance
To bring the root CA online when authorizing new intermediate CAs
What is the purpose of OCSP stapling in PKI?
To replace the need for the CRL
To validate an organization's legal existence
To bring the root CA online only when necessary
To provide a quick check of the status of a certificate
In which trust model does each CA issue certificates to each other without a subordinate relationship?
Single trust model
Hierarchical model
Mesh model
Bridge model
What is a characteristic of the Single trust model in a trust model configuration?
Multiple CAs are configured to issue certificates to each other
All users trust the CA, and there are no trusts with other CAs
Certificates are issued by a single CA with a subordinate relationship
It is a hybrid model connecting hierarchical models of two organizations
What is the primary purpose of key escrow in private key safety?
To simplify the backup process of private keys
To back up private keys by the CA
To ensure data can always be recovered
To send keys to a trusted 3rd party for security and legal purposes
