easyMultiple ChoiceObjective-mapped
Understanding PKI Components: CA, RA, CRL, and VA
In a public key infrastructure (PKI), which component is responsible for issuing and revoking digital certificates?
Quick Answer
The answer is the Certificate Authority (CA). The CA is the correct choice because it serves as the trusted root in a public key infrastructure, responsible for the full lifecycle of digital certificates—issuing them by signing with its private key and revoking them by publishing Certificate Revocation Lists (CRLs) or through the Online Certificate Status Protocol (OCSP). On the CISSP exam, this question tests your understanding of PKI components like the CA, RA (Registration Authority), and VA (Validation Authority), often appearing in domain 3 (Security Architecture and Engineering). A common trap is confusing the RA’s role in verifying identity with the CA’s authority to actually issue or revoke certificates. Remember: the CA is the “issuer and revoker,” while the RA is the “verifier.” A useful memory tip is to think of the CA as the central bank of trust—it alone prints and destroys the currency of certificates.
⚠ Common exam trap
A common mix-up: candidates confuse the Registration Authority (RA) with the Certificate Authority (CA), as the RA performs identity verification but candidates often mistakenly think it also issues certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate Authority (CA)
The Certificate Authority (CA) is the trusted entity in a PKI that issues digital certificates by signing them with its private key, and it also revokes certificates by publishing Certificate Revocation Lists (CRLs) or using the Online Certificate Status Protocol (OCSP). The CA is the authoritative source for certificate lifecycle management, including issuance, renewal, and revocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Registration Authority (RA)
Why it's wrong here
RA verifies identity but does not issue or revoke certificates.
- ✓
Certificate Authority (CA)
Why this is correct
Correct. CA issues and revokes certificates in a PKI.
- ✗
Certificate Revocation List (CRL)
Why it's wrong here
CRL is a list of revoked certificates, not an issuing authority.
- ✗
Validation Authority (VA)
Why it's wrong here
VA provides certificate status checks via OCSP but does not issue.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISSP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Match each PKI component to its function.
medium- ✓ A.Certificate Authority (CA): Issues and signs digital certificates
- ✓ B.Registration Authority (RA): Verifies identity and requests certificate issuance
- ✓ C.Certificate Repository: Stores and distributes public key certificates
- ✓ D.Certificate Revocation List (CRL): Lists revoked certificates
- E.Certificate Authority (CA): Stores and distributes certificates
- F.Registration Authority (RA): Issues and signs certificates
Why A: In PKI, the CA issues and signs certificates, the RA verifies identities, the repository stores certificates for retrieval, and the CRL tracks revoked certificates. Common confusions involve mixing the roles of CA and RA or CA and repository.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.