Courseiva
General Security ConceptseasyMatchingObjective-mapped

SY0-701 General Security Concepts Practice Question

Match each PKI term to what it does.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Issues and signs digital certificates.

Binds an identity to a public key.

Can be shared with others to encrypt data or verify signatures.

Must be kept secret and is used to decrypt or sign.

Removes trust from a certificate that should no longer be used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

CA: Issues and manages digital certificates

CA issues certificates, RA verifies identities, CRL lists revoked certificates, public key encrypts, private key decrypts, digital signature provides integrity and non-repudiation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • CA: Issues and manages digital certificates

    Why this is correct

    The Certificate Authority (CA) is the trusted PKI component that creates, signs, and handles the full lifecycle of digital certificates, including issuance, renewal, and revocation. It holds a private key used to sign each certificate, binding a subject's public key to its identity and making the certificate verifiable by relying parties. Without a CA, there is no trustworthy cryptographic link between an identity and a public key.

  • RA: Verifies identity of certificate requestors

    Why this is correct

    The Registration Authority (RA) is an optional component that acts as the front-end to the CA by performing identity proofing and verification of entities requesting certificates. It validates the requestor's information, authenticates the entity, and forwards approved requests to the CA; it does not have certificate-signing authority. In high-security environments, separating the RA from the CA ensures no single entity can both vet and issue without oversight.

  • CRL: Lists revoked certificates

    Why this is correct

    The Certificate Revocation List (CRL) is a certificate-holder-specific data structure published by the CA that enumerates the serial numbers or identifiers of certificates revoked before their scheduled expiration. Clients and relying parties check the CRL during validation to determine whether a presented certificate should be considered untrusted, even if the certificate's digital signature is valid. A CRL is not an active authority; it is merely a time-stamped inventory that the CA maintains and distributes.

  • CA: Verifies identity of certificate requestors

    Why it's wrong here

    Although a CA may also conduct identity checks in some small or integrated deployments, the PKI term specifically responsible for verifying certificate requestors is the Registration Authority (RA). The RA acts as the gatekeeper for identity proofing and forwards only vetted requests to the CA, which then issues the certificate. Assigning this identity-verification function solely to the CA conflates two distinct PKI roles and is therefore incorrect.

  • RA: Issues and manages digital certificates

    Why it's wrong here

    The RA does not issue or manage digital certificates; it lacks the CA's private key and signing authority. Its role is limited to authenticating applicants and forwarding legally or procedurally approved certificate requests to the CA. Management of issued certificates—including signature creation, renewal, and revocation—remains the exclusive responsibility of the CA, so this statement is incorrect.

  • CRL: Issues and manages digital certificates

    Why it's wrong here

    The CRL is not a PKI entity or authority and cannot issue digital certificates; it is simply a list that reports revoked certificates. It contains no private key and performs no signing operations, so it has no capability to create or manage certificates. Only the CA can issue and manage certificates, while the CRL serves as a passive, published source of revocation information for clients to consult.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.