
EC-CouncilCertified Encryption Specialist
Domain 4Objective 2
PKI Infrastructure and Kerberos Authentication ECES Practice Questions (Page 3)
Part of the Applications of Cryptography domain, which makes up ~25% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
7concepts
Questions 11–15
- 11
What is the primary purpose of the certificate revocation stage in the certificate lifecycle?
Select an answer first - 12
In the certificate lifecycle, what is the correct order of the first three stages after a certificate is created?
Select an answer first - 13
An organization issues client certificates to employees for email signing. A certificate was issued with a validity period of two years, but an employee leaves the company after six months. The security team wants to ensure that the departed employee's certificate can no longer be used for signing. What is the most appropriate action?
Select an answer first - 14
When a client validates a certificate, what does it use to verify that the certificate is not revoked?
Select an answer first - 15
A Kerberos ticket contains a session key encrypted with the service's long-term key. What is the primary purpose of this design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.