GSEC Cryptography Application Practice Question
Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?
⚠ Common exam trap
Candidates often select 'encryption' or 'hashing' as primary PKI functions. While PKI uses these technologies, its primary purpose is the management of identity through certificate issuance and revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Issuance of digital certificates to verify identity.
PKI is vital for managing the lifecycle of digital certificates, ensuring trust in identity. By providing mechanisms for issuance and revocation, PKI allows entities to communicate securely without pre-existing trust. Understanding these functions is essential for GSEC professionals to manage authentication and secure communication channels effectively within an enterprise architecture, preventing the use of expired or fraudulent credentials that could be exploited by malicious actors during network sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Centralized distribution of symmetric keys.
Why it's wrong here
Symmetric key distribution is handled by protocols like Kerberos or Key Management Systems, not PKI. PKI specifically focuses on the management of asymmetric key pairs and the verification of identities through X.509 certificates rather than the direct transmission of secret symmetric keys between various network clients.
- ✓
Issuance of digital certificates to verify identity.
Why this is correct
Issuing digital certificates is a core function of the Certificate Authority (CA) within a PKI. These certificates bind a public key to a specific entity, allowing other parties to verify that the entity is who they claim to be, which is fundamental to establishing trust online.
- ✓
Revocation of compromised or invalid certificates.
Why this is correct
Certificate revocation is a mandatory function of PKI. When a private key is compromised or a certificate is no longer needed, the CA must publish this information via Certificate Revocation Lists (CRLs) or OCSP, ensuring that untrusted or fraudulent certificates are no longer accepted by relying parties.
- ✗
Hardware-level encryption for disk storage.
Why it's wrong here
Disk encryption is typically handled by Full Disk Encryption (FDE) tools or platform-specific features like BitLocker or dm-crypt. While PKI might assist in managing the keys for such systems, it is not the primary function of the infrastructure itself, which is designed for identity and trust management.
- ✗
Real-time traffic flow monitoring and alerting.
Why it's wrong here
Traffic monitoring and alerting are the responsibilities of Intrusion Detection and Prevention Systems (IDPS) or Network Monitoring Tools. PKI does not provide analysis of packet contents or network behavior, as its operational focus remains strictly on the management of public key assets and digital identity authentication.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.