exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 480 discussion

Actual exam question from Cisco's 350-701
Question #: 480
Topic #: 1
[All 350-701 Questions]

What is the purpose of CA in a PKI?

  • A. to validate the authenticity of a digital certificate
  • B. to issue and revoke digital certificates
  • C. to certify the ownership of a public key by the named subject
  • D. to create the private key for a digital certificate
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Girmiti
4 days, 13 hours ago
Selected Answer: B
B is the correct answer. https://community.cisco.com/t5/security-knowledge-base/ca/ta-p/3114159#:~:text=As%20part%20of%20a%20public%20key%20infrastructure%20%28PKI%29%2C,information%2C%20the%20CA%20can%20then%20issue%20a%20certificate.
upvoted 1 times
...
ton99
2 months, 1 week ago
The answer is B: "Vetting (verifying) the identity of the website owner or organization: When you request a certificate from CA, it verifies the information you provide. This information includes the organization’s name, domain name, address, email address and a public key.....If the certification authority realizes it has improperly issued a certificate, it revokes the certificate and issues a new one for the same entity. If the CA discovers that the certificate used by an entity is a counterfeit, it revokes the certificate and adds it to the Certificate Revocation List (CRL)."
upvoted 1 times
...
Demon_Queen_Velverosa
3 months, 1 week ago
Selected Answer: B
The answer is B
upvoted 1 times
...
Premium_Pils
4 months, 3 weeks ago
Selected Answer: B
The question is based on the wikipedia: https://en.wikipedia.org/wiki/Certificate_authority "In cryptography, a certificate authority or certification authority (CA) is an entity that stores, signs, and issues digital certificates." You can find answer C) word by word there. A digital certificate certifies the ownership of a public key by the named subject of the certificate. This allows others (relying parties) to rely upon signatures or on assertions made about the private key that corresponds to the certified public key. ...and a similar description to A) The certificate is also a confirmation or validation by the CA that the public key contained in the certificate belongs to the person, organization, server or other entity noted in the certificate.
upvoted 1 times
Premium_Pils
4 months, 3 weeks ago
Wikipedia seems to align with answer B). A) would be correct, if it would say validation of a public key contained in a certificate.
upvoted 1 times
Premium_Pils
4 months, 3 weeks ago
C) explains what a certificate is, and not what a CA is. The question is about defining the CA.
upvoted 1 times
...
...
...
Bubu3k
6 months ago
Selected Answer: C
I'm with Tthurston1 on this one, so C. I might be wrong, but, at the end of the day, the CA is there to confirm that only the subject can decrypt the message encrypted with its public key and that a message that can be decrypted with the public key was definitely encrypted by the subject via private. In my view C is the scope, A&B are processes done in order to achieve the goal.
upvoted 1 times
...
Mocix
6 months, 1 week ago
Selected Answer: B
CA doesn't directly validate any certificate. If you want to check if a certificate is valide, you just check if it's signed by CA( or above) and if it is still valid! So, A can not be correct! I go for B.
upvoted 1 times
Tthurston1
5 months, 3 weeks ago
??? Where's your source to backup such a claim? On the contrary, CA's DO VALIDATE certificates! Taken from: www.digicert.com/blog/what-is-a-certificate-authority "However, CAs VALIDATE organizations and individuals to help ensure that only legitimate websites get a TLS certificate." "Before issuing a certificate, the CA WILL VERIFY the certificate requester’s information, like site ownership, name, location and more. CAs must adhere to stringent industry standards to ensure that every CA follows similar requirements for validation."
upvoted 1 times
...
...
Tthurston1
6 months, 4 weeks ago
Selected Answer: C
In the grand scheme of things, Options A-C are ALL VALID functions of a CA in a PKI infrastructure. But of course, you can only choose one answer..... I would opt for Option C because it emphasizes the critical aspect of verifying ownership of the PUBLIC key by the named subject.
upvoted 1 times
Tthurston1
6 months, 4 weeks ago
The CA acts as a trusted entity in a PKI, verifying the identity of entities requesting digital certificates and issuing certificates that bind a public key to a trusted subject. This binding of identity to a public key is the foundation of trust in PKI-based secure communication.
upvoted 1 times
...
...
not_so_free
10 months, 3 weeks ago
They are asking for CA not RootCA certificate, might be B, make more sense to me.
upvoted 1 times
...
mikexian
11 months, 4 weeks ago
In a PKI (Public Key Infrastructure), the purpose of a CA (Certificate Authority) is to issue, manage, and revoke digital certificates. The CA plays a central role in establishing trust and enabling secure communication within the PKI ecosystem. Here are the key purposes of a CA:
upvoted 2 times
...
CCNPWILL
1 year, 1 month ago
Selected Answer: A
I agree. A is the most ligical for a CA in PKI setup.
upvoted 2 times
...
ytsionis
1 year, 3 months ago
A is the only right. Issuing a digital certificate can be done also by an internal custom CA with no validity to the outside word.
upvoted 4 times
...
mazimir
1 year, 6 months ago
I would argue here, it could be A) as well. I as user or scripts are able to "issue" or "revoke" certificates, but only CA can grant authenticity...
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago