Courseiva
easyMultiple Choice

Understanding PKI Components: CA, RA, CRL, and VA

In a public key infrastructure (PKI), which component is responsible for issuing and revoking digital certificates?

Quick Answer

The answer is the Certificate Authority (CA). The CA is the correct choice because it serves as the trusted root in a public key infrastructure, responsible for the full lifecycle of digital certificates—issuing them by signing with its private key and revoking them by publishing Certificate Revocation Lists (CRLs) or through the Online Certificate Status Protocol (OCSP). On the CISSP exam, this question tests your understanding of PKI components like the CA, RA (Registration Authority), and VA (Validation Authority), often appearing in domain 3 (Security Architecture and Engineering). A common trap is confusing the RA’s role in verifying identity with the CA’s authority to actually issue or revoke certificates. Remember: the CA is the “issuer and revoker,” while the RA is the “verifier.” A useful memory tip is to think of the CA as the central bank of trust—it alone prints and destroys the currency of certificates.

⚠ Common exam trap

A common mix-up: candidates confuse the Registration Authority (RA) with the Certificate Authority (CA), as the RA performs identity verification but candidates often mistakenly think it also issues certificates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate Authority (CA)

The Certificate Authority (CA) is the trusted entity in a PKI that issues digital certificates by signing them with its private key, and it also revokes certificates by publishing Certificate Revocation Lists (CRLs) or using the Online Certificate Status Protocol (OCSP). The CA is the authoritative source for certificate lifecycle management, including issuance, renewal, and revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Registration Authority (RA)

    Why it's wrong here

    The RA verifies subscriber identity and forwards requests, but the CA signs and issues certificates and publishes revocation lists. It is tempting because the RA handles registration and identity proofing, yet issuance and revocation are certificate authority functions, making the CA the correct component.

  • ✓

    Certificate Authority (CA)

    Why this is correct

    The Certificate Authority signs and publishes certificates, binding a public key to an identity, and maintains the CRL or OCSP responder for revocation. No other PKI component holds both issuing and revoking authority, satisfying the stem's dual requirement.

  • ✗

    Certificate Revocation List (CRL)

    Why it's wrong here

    A CRL only publishes the serial numbers of certificates already revoked by the CA; it cannot issue or revoke them itself. It is tempting because revocation is genuinely part of the PKI lifecycle, and a CRL is the artefact clients query to check revocation status — but the issuing authority, not the list, performs both operations.

  • ✗

    Validation Authority (VA)

    Why it's wrong here

    A Validation Authority answers revocation-status queries such as OCSP, confirming whether a certificate is still valid; it never issues or revokes certificates. It is tempting because it is certificate-related, and would be correct for real-time status checking during authentication.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each PKI component to its function.

medium
  • ✓ A.Certificate Authority (CA): Issues and signs digital certificates
  • ✓ B.Registration Authority (RA): Verifies identity and requests certificate issuance
  • ✓ C.Certificate Repository: Stores and distributes public key certificates
  • ✓ D.Certificate Revocation List (CRL): Lists revoked certificates
  • E.Certificate Authority (CA): Stores and distributes certificates
  • F.Registration Authority (RA): Issues and signs certificates

Why A: In PKI, the CA issues and signs certificates, the RA verifies identities, the repository stores certificates for retrieval, and the CRL tracks revoked certificates. Common confusions involve mixing the roles of CA and RA or CA and repository.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.