An information security architect is designing a public key infrastructure (PKI) to support mutual TLS authentication across hundreds of internal microservices deployed worldwide. The architect can either rely on individually trusted self-signed certificates, a web-of-trust model, or build an internal X.509 certificate-authority hierarchy. Which advantage of using a certificate-authority hierarchy BEST supports the architect's decision?
Removal of private key material from the environment
Reduced cryptographic processing load on service instances
Centralized trust anchor and automated certificate lifecycle management
Guaranteed prevention of all man-in-the-middle attacks
A certificate authority (CA) provides a single, vetted trust anchor that issues, renews, and revokes digital certificates for every service. Centralizing these lifecycle tasks simplifies administration, enforces consistent policy, and allows relying parties to validate any certificate by following the chain back to that trusted root. Although CAs improve trust scalability, they do not lower cryptographic processing demands, remove the need for private keys, or make man-in-the-middle attacks impossible when the CA or validation process is compromised.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Certificate Authority (CA) in PKI?
Open an interactive chat with Bash
Why is centralized management important in PKI?
Open an interactive chat with Bash
How does a CA mitigate man-in-the-middle attacks?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .