
EC-CouncilNetwork Defense Essentials
Domain 6Objective 2
Public Key Infrastructure (PKI) and Digital Certificates NDE Practice Questions (Page 5)
Part of the Cryptography, PKI, and Data Security domain, which makes up ~15% of our current practice bank.
44questions here
9free pages
10concepts
Questions 21–25
- 21
An organization is implementing a PKI and wants to ensure that the root CA's private key is protected from theft. Which practice is the most effective for safeguarding the root CA private key?
Select an answer first - 22
A security administrator discovers that an employee's private key was exposed in a data breach. The employee's certificate is still valid and used for email signing. What is the most immediate action the administrator should take to prevent further misuse?
Select an answer first - 23
A software vendor signs its releases with a code-signing certificate. A security researcher discovers a vulnerability in the vendor's signing process that could allow an attacker to sign malicious code with the vendor's certificate. The vendor wants to minimize the impact on existing customers while addressing the vulnerability. Which action should the vendor take first?
Select an answer first - 24
What is the purpose of a Certificate Revocation List (CRL) published by a CA?
Select an answer first - 25
A software vendor wants to distribute a signed update to customers. The vendor uses a code-signing certificate. Which key must the vendor use to create the digital signature, and which key do customers use to verify it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.