📖 What is PKI?

Public Key Infrastructure (PKI) is a comprehensive system for managing digital certificates, public and private key pairs, and Certificate Authorities (CAs). It establishes a trusted framework for secure communication and authentication by verifying identities and enabling encrypted data exchange.

🥋 Sensei Says:

"Understand the components of a PKI: Registration Authorities (RAs), Certificate Revocation Lists (CRLs), and Online Certificate Status Protocol (OCSP). Be prepared to discuss the trust model inherent in PKI and the potential risks associated with compromised CAs. Know the different certificate types and their intended uses."

📚 Certification: Certified Information Systems Security Professional (CISSP)

🔑 What are the Key Concepts of PKI?

  • PKI relies on a hierarchical trust model, starting with a Root CA and extending to subordinate CAs, ensuring certificate validity through chain of trust.
  • Digital certificates bind a public key to an identity, enabling verification of authenticity and integrity during communication and transactions.
  • Certificate Revocation Lists (CRLs) and Online Certificate Status Protocol (OCSP) are crucial for determining if a certificate is still valid and hasn’t been compromised.
  • Registration Authorities (RAs) verify the identity of certificate applicants before submitting requests to the CA, adding a layer of security.
  • Understanding certificate types (SSL/TLS, code signing, email) and their specific uses is vital for applying PKI effectively.

🎯 How does PKI appear on the CISSP Exam?

You may be asked to identify the component responsible for verifying the identity of an entity requesting a digital certificate within a PKI system.

A scenario might describe a security incident involving a compromised Certificate Authority – expect questions about the impact and mitigation strategies.

Expect questions about choosing the appropriate certificate revocation method (CRL vs. OCSP) based on performance and real-time validation requirements.

❓ Frequently Asked Questions

What is the difference between a Root CA and an Intermediate CA?

A Root CA is self-signed and at the top of the trust hierarchy. Intermediate CAs are signed by the Root CA and issue certificates to end entities, reducing risk to the Root CA.


How does OCSP differ from CRLs in terms of certificate status checking?

OCSP provides real-time certificate status verification, while CRLs are periodically updated lists. OCSP is generally faster and more efficient, but relies on a functioning OCSP responder.


What are the implications of a compromised private key associated with a CA?

A compromised CA private key is a catastrophic event. All certificates issued by that CA are no longer trustworthy and must be revoked, requiring a complete re-issuance process.

Related Terms from Certified Information Systems Security Professional

📝 Related Study Guides

Study Guide 10 min read

How to Pass the CISSP Exam: A Realistic 2026 Study Plan

To pass the CISSP, you must transition from a technical mindset to a managerial one, focusing on risk management and policy over implementation. Success requires a 3-6 month study plan covering all eight domains, using adaptive practice exams to identify gaps and mastering the "mile wide, inch deep" breadth of the CBK.

Career Guide 10 min read

CISSP Experience Requirements: How to Get Your Waiver in 2026

To earn the CISSP, you need five years of cumulative, paid work experience in two or more of the eight CISSP domains. You can obtain a one-year waiver through a four-year college degree or approved professional certifications. Those lacking full experience can become an Associate of ISC2 after passing the exam.

Deep Dive 8 min read

Kerberos Authentication Explained for the CISSP Exam

Kerberos is a ticket-based authentication protocol designed to provide strong authentication for client/server applications by using secret-key cryptography. It utilizes a trusted third party called the Key Distribution Center (KDC) to issue tickets, enabling Single Sign-On (SSO) and preventing replay attacks through the use of synchronized timestamps.

🧠

Test Your Knowledge

Think you understand PKI? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium