Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which THREE of the following are components of PKI (Public Key Infrastructure)?

⚠ Common exam trap

CEH often tests whether candidates can distinguish PKI's foundational components (CA, key pairs, certificates) from technologies that merely use PKI (RADIUS, WPA3, TLS), so protocol names are inserted as distractors to catch rote memorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate Authority (CA)

A Certificate Authority (CA) is a core PKI component because it issues, signs, and revokes digital certificates, binding a public key to an identity. A private key and public key pair is essential to PKI since asymmetric cryptography underpins key exchange, digital signatures, and certificate ownership. Digital certificates are also fundamental PKI components, as they are the signed X.509 structures that convey a subject's public key and identity, validated through the CA's trust chain. WPA3 is a Wi-Fi security certification/protocol standard, not a PKI component, and a RADIUS server is an AAA (authentication, authorization, accounting) server often used for network access control, not a defining element of PKI itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Certificate Authority (CA)

    Why this is correct

    A Certificate Authority (CA) is a trusted third party that issues, manages, and revokes digital certificates. Its primary role within a Public Key Infrastructure (PKI) is to verify the identity of entities (users, devices, services) and bind their public keys to that identity through a signed digital certificate. CAs are fundamental to establishing trust in a PKI, as relying parties implicitly trust certificates signed by a CA they recognize.

  • ✗

    WPA3

    Why it's wrong here

    WPA3 (Wi-Fi Protected Access 3) is a security certification program and protocol suite designed to secure wireless local area networks (WLANs). While it enhances Wi-Fi security through stronger encryption and authentication methods, it is a standard for protecting wireless communication channels, not a core architectural component of a Public Key Infrastructure itself. PKI deals with identity verification and key management, whereas WPA3 focuses on securing the wireless medium.

  • ✓

    Private key and public key pair

    Why this is correct

    The private key and public key pair is the cryptographic cornerstone of asymmetric encryption, which underpins PKI. The public key is freely distributed and used to encrypt data or verify digital signatures, while the corresponding private key is kept secret by its owner and used to decrypt data or create digital signatures. This pair enables secure communication and authentication without sharing a secret key, forming the basis for digital certificate functionality.

  • ✓

    Digital certificates

    Why this is correct

    Digital certificates are electronic documents that cryptographically bind a public key to an entity's identity, such as a person, organization, or device. Issued by a Certificate Authority, they contain information like the public key, the entity's name, the issuer's name, and a validity period, all digitally signed by the CA. These certificates are crucial for verifying the authenticity of public keys and establishing trust in a PKI environment.

  • ✗

    RADIUS server

    Why it's wrong here

    A RADIUS (Remote Authentication Dial-In User Service) server is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for users connecting to a network service. While essential for network access control and often used in conjunction with security protocols, a RADIUS server's function is distinct from the core components of a Public Key Infrastructure. PKI focuses on identity verification and key management through certificates, not direct user authentication for network access.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.