Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 6Objective 2

Public Key Infrastructure (PKI) and Digital Certificates NDE Practice Questions (Page 8)

Part of the Cryptography, PKI, and Data Security domain, which makes up ~15% of our current practice bank.

44questions here
9free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A company is planning to issue certificates to external partners. They want to ensure that the identity of each partner is verified according to the company's policy, but they do not want to expose their internal CA to the internet. Which architecture should they use?

    Select an answer first
  2. 37application · medium

    A company is setting up a PKI and wants to separate the identity verification process from the certificate signing process to improve security and scalability. Which architecture should they implement?

    Select an answer first
  3. 38foundation · easy

    What is the primary role of a Certificate Authority (CA) in a PKI?

    Select an answer first
  4. 39foundation · easy

    In a public key cryptosystem, which key is used to encrypt a message that only the intended recipient can decrypt?

    Select an answer first
  5. 40application · medium

    A web application needs to check the revocation status of client certificates in real time during the TLS handshake. The application requires low latency and does not want to download large lists. Which revocation mechanism should the application use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.