Courseiva
Cryptography Application →mediumMultiple Select

GSEC Cryptography Application Practice Question

Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?

⚠ Common exam trap

Candidates often select 'encryption' or 'hashing' as primary PKI functions. While PKI uses these technologies, its primary purpose is the management of identity through certificate issuance and revocation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Issuance of digital certificates to verify identity.

PKI is vital for managing the lifecycle of digital certificates, ensuring trust in identity. By providing mechanisms for issuance and revocation, PKI allows entities to communicate securely without pre-existing trust. Understanding these functions is essential for GSEC professionals to manage authentication and secure communication channels effectively within an enterprise architecture, preventing the use of expired or fraudulent credentials that could be exploited by malicious actors during network sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Centralized distribution of symmetric keys.

    Why it's wrong here

    Symmetric key distribution is handled by protocols like Kerberos or Key Management Systems, not PKI. PKI specifically focuses on the management of asymmetric key pairs and the verification of identities through X.509 certificates rather than the direct transmission of secret symmetric keys between various network clients.

  • ✓

    Issuance of digital certificates to verify identity.

    Why this is correct

    Issuing digital certificates is a core function of the Certificate Authority (CA) within a PKI. These certificates bind a public key to a specific entity, allowing other parties to verify that the entity is who they claim to be, which is fundamental to establishing trust online.

  • ✓

    Revocation of compromised or invalid certificates.

    Why this is correct

    Certificate revocation is a mandatory function of PKI. When a private key is compromised or a certificate is no longer needed, the CA must publish this information via Certificate Revocation Lists (CRLs) or OCSP, ensuring that untrusted or fraudulent certificates are no longer accepted by relying parties.

  • ✗

    Hardware-level encryption for disk storage.

    Why it's wrong here

    Disk encryption is typically handled by Full Disk Encryption (FDE) tools or platform-specific features like BitLocker or dm-crypt. While PKI might assist in managing the keys for such systems, it is not the primary function of the infrastructure itself, which is designed for identity and trust management.

  • ✗

    Real-time traffic flow monitoring and alerting.

    Why it's wrong here

    Traffic monitoring and alerting are the responsibilities of Intrusion Detection and Prevention Systems (IDPS) or Network Monitoring Tools. PKI does not provide analysis of packet contents or network behavior, as its operational focus remains strictly on the management of public key assets and digital identity authentication.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.