200-201 Security Concepts Practice Question
In a PKI, what is the role of a Certificate Authority (CA)?
⚠ Common exam trap
200-201 often tests the misconception that the CA generates private keys or performs encryption; candidates must remember that the CA only issues and validates certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Issues and validates digital certificates
A Certificate Authority (CA) is a trusted entity that issues and validates digital certificates. It verifies the identity of certificate applicants and signs the certificates with its private key, thereby binding a public key to an identity. This is the core function of a CA in a PKI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generates private keys for users
Why it's wrong here
A CA signs and issues certificates binding public keys to identities; it never generates users' private keys, which must stay secret with the subscriber. Key generation is performed by the end entity or its key store. The CA's signing role is tempting because it does handle key material, but only public keys within certificates.
- ✗
Provides symmetric keys for session encryption
Why it's wrong here
A CA issues and signs digital certificates binding public keys to identities; it never generates or distributes symmetric session keys, which are negotiated separately by the communicating parties. The option tempts because CAs are trusted key authorities, but their role is asymmetric key certification, not bulk symmetric key distribution.
- ✗
Encrypts data for secure transmission
Why it's wrong here
Encryption of transmitted data is performed by protocols such as TLS using session keys; the CA only vouches for the authenticity of public keys via signed certificates. Its role is trust establishment, not bulk data confidentiality. This is tempting because certificates enable encryption, but the CA itself does not encrypt traffic.
- ✓
Issues and validates digital certificates
Why this is correct
The CA is the trusted third party within a PKI that issues digital certificates, binding a public key to a verified identity, and validates those certificates through its registration and revocation processes. This satisfies the stem's requirement for trusted certificate issuance and validation.
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.