nerdexam
Isaca

CISA · Question #406

How does an organization indicate the authenticity of its web pages for users utilizing a public key infrastructure (PKI)?

The correct answer is B. By purchasing digital certificates from trusted third parties. In a PKI environment, authenticity is established through digital certificates issued by a trusted Certificate Authority (CA)-a trusted third party. The CA validates the organization's identity before issuing the certificate, giving users a basis for trust. Self-created or intern

Submitted by weili_xi· Apr 18, 2026Protection of Information Assets

Question

How does an organization indicate the authenticity of its web pages for users utilizing a public key infrastructure (PKI)?

Options

  • ABy including trademark logos with the organization's name and physical address
  • BBy purchasing digital certificates from trusted third parties
  • CBy creating digital certificates internally and applying a stamp of authenticity
  • DBy coding the page utilizing Hypertext Transmission Protocol Secure (HTTPS)

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    88% (44)
  • C
    6% (3)
  • D
    2% (1)

Explanation

In a PKI environment, authenticity is established through digital certificates issued by a trusted Certificate Authority (CA)-a trusted third party. The CA validates the organization's identity before issuing the certificate, giving users a basis for trust. Self-created or internally issued certificates (C) provide no external trust anchor because there is no independent party vouching for the organization's identity. Trademark logos and addresses (A) can be easily spoofed and are not cryptographic. HTTPS (D) is the transport protocol that uses the certificate but does not by itself confer authenticity-the certificate behind it does.

Topics

#PKI#Digital Certificates#Web Security#Authenticity

Community Discussion

No community discussion yet for this question.

Full CISA Practice