Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security architect is designing a PKI hierarchy for a large enterprise that issues certificates for internal users, devices, and code signing. Which of the following best practices should be implemented to minimize the impact of a CA compromise?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a segmented CA hierarchy with offline root CA and separate issuing CAs for each purpose

Using a tiered CA hierarchy with a root CA that remains offline and issuing CAs for specific purposes limits exposure. If an issuing CA is compromised, only its certificates need to be revoked, and the root CA can issue a new subordinate CA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rely on certificate transparency logs to detect compromises

    Why it's wrong here

    Certificate transparency logs record issued certificates for public web PKI monitoring; they do not constrain an internal CA compromise or limit which certificates that CA can mint. Transparency is tempting for detecting mis-issuance in public TLS, but it provides detection, not the containment that offline roots and segregated issuing CAs deliver.

  • ✗

    Keep the root CA online for immediate certificate revocation

    Why it's wrong here

    An online root CA exposes the trust anchor to network attack, so compromise of that host collapses the entire hierarchy. Keeping it online is tempting for immediate CRL or OCSP publishing, but an offline root with online subordinate CAs achieves revocation while shielding the anchor from direct compromise.

  • ✗

    Use a single CA for all certificate types to reduce complexity

    Why it's wrong here

    A single CA for all certificate types concentrates trust, so one compromise invalidates every user, device and code-signing certificate simultaneously. Consolidation is tempting for operational simplicity in small environments, but a tiered hierarchy with separate issuing CAs for each certificate class confines the blast radius of any single CA compromise.

  • ✓

    Implement a segmented CA hierarchy with offline root CA and separate issuing CAs for each purpose

    Why this is correct

    An offline root CA issues only to subordinate issuing CAs, each scoped to one purpose, so compromising a user-issuing CA cannot forge code-signing or device certificates. This satisfies the constraint of minimising compromise blast radius through cryptographic and operational separation.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.