CAS-004 Security Engineering Practice Question
An organization is planning to deploy a new internal CA hierarchy. Which THREE considerations are critical for ensuring the security and manageability of the PKI?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Keep the root CA offline and only bring it online for cross-certification or disaster recovery.
Option A is correct because keeping the root CA offline (air-gapped) protects the trust anchor's private key from compromise, bringing it online only for cross-certification or disaster recovery, which is a foundational PKI best practice. Option B is correct because using a 4096-bit RSA key for the long-lived root CA and at least 2048-bit keys for issuing CAs provides adequate cryptographic strength for the hierarchy's lifetime and resists brute-force attacks. Option E is correct because embedding CRL distribution points and OCSP responder URLs in certificates enables timely revocation checking, which is essential for security and manageability of the PKI. Option C is incorrect because SHA-1 is deprecated and vulnerable to collision attacks; SHA-256 or stronger should be used. Option D is incorrect because a single-tier CA exposes the root to online issuance risks and reduces flexibility, whereas a multi-tier hierarchy with an offline root is more secure and manageable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Keep the root CA offline and only bring it online for cross-certification or disaster recovery.
Why this is correct
Keeping the root CA offline means its private key is never exposed on a network-connected host, so compromise of subordinate systems cannot forge the trust anchor. It is brought online only for cross-certification or disaster recovery, preserving hierarchy integrity and manageability.
- ✓
Use a 4096-bit RSA key for the root CA and at least 2048-bit for issuing CAs.
Why this is correct
A 4096-bit root key resists brute-force attacks over its long lifespan, while 2048-bit issuing keys balance security with performance for frequent signing. This satisfies the stem's requirement for a secure, manageable hierarchy by matching key strength to each CA's role and exposure.
- ✗
Use SHA-1 for certificate signing to ensure compatibility with legacy systems.
Why it's wrong here
SHA-1 is cryptographically broken for certificate signing, so collisions permit forged certificates within the hierarchy. It is tempting because legacy clients may only accept SHA-1, but the correct choice is SHA-256 or stronger, which modern systems support and which preserves trust.
- ✗
Use a single-tier CA to simplify management.
Why it's wrong here
A single-tier CA places the root online to issue certificates, exposing the trust anchor to compromise with no intermediate to revoke. It is tempting because fewer components reduce administrative overhead, but the correct design keeps the root offline and delegates issuance to subordinate CAs.
- ✓
Ensure all certificates include CRL distribution points and OCSP responder URLs.
Why this is correct
Embedding CRL distribution points and OCSP responder URLs in every certificate lets relying parties check revocation status without contacting the issuing CA directly, satisfying the manageability and security requirement for a scalable internal hierarchy. Without these extensions, revoked certificates remain trusted until expiry, undermining the PKI's ability to respond to compromise.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.