Question 1
An organization is building its own Public Key Infrastructure (PKI). The security architect has designed a two-tier hierarchy with an offline Root CA and an online Intermediate CA. The Intermediate CA will be responsible for signing certificates for all internal web servers.
The diagram below shows the intended signing process. What is the most critical security measure for protecting the long-term integrity of this entire PKI?
Answer and explanation
Correct answer: A
The entire trust of a PKI rests on the security of the Root CA's private key. If this key is compromised, an attacker can issue fraudulent certificates that will be trusted by all clients, completely undermining the infrastructure. Therefore, the most critical security control is to keep the Root CA offline, powered down, and physically secured in an air-gapped environment. It should only be brought online in a controlled manner to sign a new Intermediate CA certificate or to update the Certificate Revocation List (CRL).