nerdexam
Isaca

CISA · Question #485

Standard operating procedures for dealing with a compromised private key are found in which element of a public key infrastructure (PKI)?

The correct answer is B. Certification practice statement. A Certification Practice Statement (CPS) is a detailed document published by a Certificate Authority (CA) that describes the policies, procedures, and practices used to issue, manage, revoke, and otherwise operate the PKI. This includes standard operating procedures for handling

Submitted by tarun92· Apr 18, 2026Protection of Information Assets

Question

Standard operating procedures for dealing with a compromised private key are found in which element of a public key infrastructure (PKI)?

Options

  • AOnline certificate status protocol
  • BCertification practice statement
  • CCertificate revocation list
  • DDigital certificate

How the community answered

(41 responses)
  • B
    93% (38)
  • C
    2% (1)
  • D
    5% (2)

Explanation

A Certification Practice Statement (CPS) is a detailed document published by a Certificate Authority (CA) that describes the policies, procedures, and practices used to issue, manage, revoke, and otherwise operate the PKI. This includes standard operating procedures for handling compromised private keys (e.g., emergency revocation steps). The Online Certificate Status Protocol (A) is a real-time protocol for checking certificate validity. A Certificate Revocation List (C) is the output of the revocation process (a list of revoked certificates), not the procedure for handling compromises. A Digital Certificate (D) is the credential itself.

Topics

#PKI#Certification Practice Statement#Key Management#Incident Response

Community Discussion

No community discussion yet for this question.

Full CISA Practice