TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.2 Cisco CyberOps Associate 2.10 ISC2 CISSP 3.6 CompTIA Security+ 1.2 ISC2 CC 4.2 NIST CSF PR.AA-03 NIST 800-53 SC-17
InteractiveSecurityFree

PKI: What Happens Next?

Something happens in the PKI: a key is stolen, a certificate expires, a fingerprint does not match. Predict what happens next, then see why.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

The lessons in this module each took one part of public key infrastructure: how a certificate is issued and checked, how trust is extended, how certificates chain from a root to a website, the different kinds of certificate, and how a certificate is revoked. Real problems do not arrive labelled with the lesson they belong to. Each scenario here describes something that happens, and you predict what comes next. Some are about the check itself: do the fingerprints match, which key verifies which certificate. Some are about choices: a wildcard or a separate certificate, a self-signed certificate for whom. Some are about what goes wrong: an expired certificate, a stolen key, a revoked certificate that the browser never asks about. If you are unsure, ask which piece of PKI the scenario is really about, then what that piece does. The reveal explains each one.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
1.2 Summarize fundamental security concepts.
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.
Cisco CyberOps Associate
2.10 Describe the impact of certificates on security
ISC2 CISSP
3.6 Select and determine cryptographic solutions
ISC2 CC
4.2 Understand network security architecture
NIST CSF
PR.AA-03 Users, services, and hardware are authenticated
NIST 800-53
SC-17 Public Key Infrastructure Certificates

Key terms

Public Key Infrastructure
PKI
A framework of hardware, software, policies, and standards used to create, manage, and distribute digital certificates.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Chain of Trust
The linked sequence of trust relationships that connects an entity back to a trusted anchor, validating each step in the hierarchy.
Wildcard Certificate
A digital certificate that uses an asterisk in the domain field to secure a domain and all of its subdomains under a single certificate and private key.
Self-Signed Certificate
A digital certificate signed by the entity that created it rather than a trusted certificate authority, providing encryption without third-party identity verification.
Certificate Revocation List
CRL
A Certificate Revocation List is a signed, time-stamped list published by a Certificate Authority that identifies digital certificates revoked before their expiration date due to key compromise, CA compromise, or policy violation.
Online Certificate Status Protocol
OCSP
Online Certificate Status Protocol is a real-time alternative to CRL-based revocation checking that allows clients to query a CA's OCSP responder to instantly determine whether a specific certificate is valid, revoked, or unknown.
Zero Trust
A security model that assumes no user or device is trusted by default and requires continuous verification.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.

Topics

Public Key Infrastructure Digital Certificates Certificate Revocation Trust Models Interactive Predict

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →