Courseiva
Security Concepts →hardMultiple Select

200-201 Security Concepts Practice Question

Which THREE components are part of a Public Key Infrastructure (PKI)? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between PKI components (CA, RA, digital certificate) and cryptographic primitives (hash functions, symmetric keys), so candidates mistakenly select hash functions or symmetric keys because they are associated with security, but they are not structural PKI components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registration Authority (RA)

A Registration Authority (RA) is a correct component because it acts as the intermediary that verifies subscriber identity and processes certificate requests before forwarding them to the CA, offloading identity-proofing duties from the CA. A digital certificate is correct because it is the core PKI artifact—an X.509 structure binding a subject's public key to identity, signed by the CA. A Certificate Authority (CA) is correct because it is the trust anchor that issues, signs, revokes, and manages certificates, and publishes CRLs or OCSP responses. A symmetric encryption key is not a PKI component; PKI is built on asymmetric key pairs, and symmetric keys are used for bulk data encryption outside the PKI trust framework. A hash function is a cryptographic primitive used within PKI (e.g., for signing and fingerprints) but is not itself a PKI component or role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Registration Authority (RA)

    Why this is correct

    The Registration Authority verifies subscriber identity and approves or rejects certificate requests before forwarding them to the Certificate Authority for issuance. It is a core PKI component, separating identity vetting from certificate signing so the CA is not exposed to untrusted request traffic.

  • ✗

    Symmetric encryption key

    Why it's wrong here

    Symmetric encryption uses one shared secret key for both encryption and decryption, so it involves no certificates, certificate authorities or asymmetric key pairs — the actual building blocks of a PKI. It is tempting because PKI does use symmetric keys for bulk data encryption, but those are issued within the framework, not a component of it.

  • ✓

    Digital certificate

    Why this is correct

    A digital certificate is the signed X.509 structure binding a public key to an identity, issued by the CA. It is the artefact that PKI participants exchange and validate, satisfying the stem's requirement for a core PKI component.

  • ✗

    Hash function

    Why it's wrong here

    A hash function is a cryptographic primitive used within PKI for integrity and signing, but it is not a PKI component; PKI comprises certificate authorities, registration authorities, repositories, and certificates. It is tempting because hashing underpins certificate signatures, so it appears integral, yet it is a tool PKI uses rather than a structural element.

  • ✓

    Certificate Authority (CA)

    Why this is correct

    The Certificate Authority signs and issues digital certificates, anchoring trust in the PKI hierarchy. It is the central issuing component that validates identities via the RA, satisfying the stem's requirement for a core PKI component.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.