Exam 350-701 All QuestionsBrowse all questions from this exam
Question 453

What is the purpose of CA in a PKI?

    Correct Answer: B

    The purpose of a Certificate Authority (CA) in a Public Key Infrastructure (PKI) is to issue and revoke digital certificates. The CA is responsible for creating trust within the PKI by managing the lifecycle of digital certificates, including their issuance, renewal, and revocation. This role ensures that only authenticated entities can use the trusted certificates for secure communications, making B the correct option.

Discussion
ytsionisOption: A

A is the only right. Issuing a digital certificate can be done also by an internal custom CA with no validity to the outside word.

mazimirOption: B

I would argue here, it could be A) as well. I as user or scripts are able to "issue" or "revoke" certificates, but only CA can grant authenticity...

mikexianOption: B

In a PKI (Public Key Infrastructure), the purpose of a CA (Certificate Authority) is to issue, manage, and revoke digital certificates. The CA plays a central role in establishing trust and enabling secure communication within the PKI ecosystem. Here are the key purposes of a CA:

CCNPWILLOption: A

I agree. A is the most ligical for a CA in PKI setup.

Bubu3kOption: C

I'm with Tthurston1 on this one, so C. I might be wrong, but, at the end of the day, the CA is there to confirm that only the subject can decrypt the message encrypted with its public key and that a message that can be decrypted with the public key was definitely encrypted by the subject via private. In my view C is the scope, A&B are processes done in order to achieve the goal.

MocixOption: B

CA doesn't directly validate any certificate. If you want to check if a certificate is valide, you just check if it's signed by CA( or above) and if it is still valid! So, A can not be correct! I go for B.

Tthurston1Option: C

In the grand scheme of things, Options A-C are ALL VALID functions of a CA in a PKI infrastructure. But of course, you can only choose one answer..... I would opt for Option C because it emphasizes the critical aspect of verifying ownership of the PUBLIC key by the named subject.

Tthurston1

The CA acts as a trusted entity in a PKI, verifying the identity of entities requesting digital certificates and issuing certificates that bind a public key to a trusted subject. This binding of identity to a public key is the foundation of trust in PKI-based secure communication.

not_so_freeOption: B

They are asking for CA not RootCA certificate, might be B, make more sense to me.