
Palo Alto NetworksCertified Cybersecurity Apprentice
Domain 7Objective 3
7.3 Identify and Describe Public Key Infrastructure (PKI) Components CYBERSECURITY-APPRENTICE Practice Questions (Page 1)
Part of the Identity Security domain, which accounts for 18% of the CYBERSECURITY-APPRENTICE exam.
24questions here
5free pages
5concepts
18%of the exam
Questions 1–5
- 1
A security engineer is designing a system where users can encrypt files for each other. They want to ensure that if a user's private key is compromised, the impact is limited to that user's data. What is the most effective design choice?
Select an answer first - 2
A company is setting up a PKI and wants to minimize the risk of compromise of the root CA. They plan to use an intermediate CA for issuing certificates to users. What is the primary benefit of this design?
Select an answer first - 3
A company wants to ensure that certificates issued to employees are trusted by all internal applications. They decide to deploy a private CA. What must be done on each client machine to ensure that certificates issued by this CA are trusted?
Select an answer first - 4
A security auditor is reviewing a system where digital signatures are used to verify software updates. The auditor wants to ensure that a compromised signing key cannot be used to sign malicious updates. What is the most effective control to implement?
Select an answer first - 5
A company is implementing a system where users can encrypt files that only a specific recipient can decrypt. They want to use asymmetric cryptography. What should they distribute to users to allow them to encrypt files for the recipient?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-APPRENTICE” is a trademark of its owner, used for identification only.