303-300 Sample Questions

303-300 Sample Questions & Answers

Cryptography such as X.509 certificates and encrypted filesystems ties with network hardening and intrusion detection, alongside mandatory and discretionary access control, hardening and monitoring hosts, and assessing vulnerabilities through penetration tests.

Launch the full 303-300 simulator →

1 free sample.

  1. Question 1Advanced

    Cryptography · X.509 Certificates and Public Key Infrastructures

    An organization is building its own Public Key Infrastructure (PKI). The security architect has designed a two-tier hierarchy with an offline Root CA and an online Intermediate CA. The Intermediate CA will be responsible for signing certificates for all internal web servers.

    The diagram below shows the intended signing process. What is the most critical security measure for protecting the long-term integrity of this entire PKI?

    graph TD subgraph "Offline / Air-gapped" RootCA[Root CA Certificate & Private Key] end subgraph "Online Network" IntermediateCA[Intermediate CA Certificate & Private Key] WebServerCert[Web Server Certificate] end RootCA --"Signs"--> IntermediateCA IntermediateCA --"Signs"--> WebServerCert

    Show answer & explanation

    Correct answer: A

    The entire trust of a PKI rests on the security of the Root CA's private key. If this key is compromised, an attacker can issue fraudulent certificates that will be trusted by all clients, completely undermining the infrastructure. Therefore, the most critical security control is to keep the Root CA offline, powered down, and physically secured in an air-gapped environment. It should only be brought online in a controlled manner to sign a new Intermediate CA certificate or to update the Certificate Revocation List (CRL).

Ready for the real thing?

The full 303-300 simulator has every exam-style question, timed mode, and instant scoring.