easyMultiple Select
CAS-004 Practice Question: Is implementing a public key infrastructure (PKI)
An organization is implementing a public key infrastructure (PKI). Which THREE of the following are essential components?
⚠ Common exam trap
CompTIA CASP+ often tests the distinction between essential PKI components (CA, RA, certificate database/CRL) and optional services (key escrow, TSA), trapping candidates who assume all listed items are mandatory for a basic PKI implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate authority (CA)
Option B (Certificate authority (CA)) is essential because the CA is the trusted entity that issues, signs, and revokes digital certificates, forming the core of any PKI. Option C (Certificate database and CRL) is essential because the PKI must store issued certificates and publish a Certificate Revocation List so relying parties can validate certificate status. Option D (Registration authority (RA)) is essential because the RA handles identity proofing and certificate enrollment requests on behalf of the CA, binding a subject's identity to its public key. Option A (Key escrow agent) is not essential; key escrow is an optional recovery mechanism used in some deployments, not a required PKI component. Option E (Time-stamping authority (TSA)) is not essential; a TSA provides trusted time proofs for non-repudiation in specific use cases but is not required for basic PKI operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Key escrow agent
Why it's wrong here
Key escrow stores copies of private keys for recovery, an optional archival control, not a core PKI component. The essential set is certificate authority, registration authority and certificate repository. Escrow would be the right answer where regulatory key-recovery mandates apply, such as encrypted-data access after employee departure.
- ✓
Certificate authority (CA)
Why this is correct
The CA is the trust anchor that issues, signs and revokes all X.509 certificates, binding public keys to verified identities. Without it, no entity can validate another's certificate, so the PKI's core assurance function cannot operate.
- ✓
Certificate database and CRL
Why this is correct
A certificate database stores issued certificates and their status, while the CRL publishes revoked certificates so relying parties can reject them. Together they satisfy the PKI requirement for lifecycle tracking and revocation checking, which the stem demands as essential components of any functioning public key infrastructure.
- ✓
Registration authority (RA)
Why this is correct
The registration authority verifies subscriber identity and authorises certificate requests before the certification authority issues them, satisfying the PKI requirement for validated enrolment. Without this identity-proofing function, certificates could be issued to unverified entities, undermining the trust model. It is therefore essential alongside the CA and certificate repository.
- ✗
Time-stamping authority (TSA)
Why it's wrong here
A TSA provides trusted proof-of-time for signatures, supporting non-repudiation, but PKI functions without it. Essential components are the certificate authority, registration authority and certificate repository. A TSA is correct where long-term signature validity must be provable, such as timestamped code-signing or legal e-discovery.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.