
EC-CouncilNetwork Defense Essentials
Domain 6Objective 2
Public Key Infrastructure (PKI) and Digital Certificates NDE Practice Questions (Page 7)
Part of the Cryptography, PKI, and Data Security domain, which makes up ~15% of our current practice bank.
44questions here
9free pages
10concepts
Questions 31–35
- 31
A company's web server certificate was compromised when an attacker gained access to the private key. The security team needs to immediately prevent clients from trusting the certificate while the new certificate is being issued. Which action should the team take first?
Select an answer first - 32
A financial institution operates a two-tier PKI: an offline root CA and an online issuing CA. The compliance team requires that all certificates be revoked within 24 hours of an employee's termination. The PKI team is concerned about the availability of the revocation checking service. Which solution best balances compliance and availability?
Select an answer first - 33
A large enterprise is designing a PKI for 50,000 users and 10,000 devices. They require high availability for certificate validation, but they also want to minimize the risk of a compromised root CA. They plan to use an offline root CA and two subordinate CAs. Which additional design choice best balances availability and security?
Select an answer first - 34
An organization's web server certificate is nearing expiration. The administrator wants to replace it without any downtime and ensure that clients do not see a security warning. Which action should the administrator take?
Select an answer first - 35
In a PKI, which entity is responsible for verifying the identity of an individual requesting a digital certificate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.