72 Crypto · TLS & PKI questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.HTTP layered over TLS to provide encrypted, authenticated web communication
B.Server Name Indication, a TLS extension letting a client specify the hostname so a server can present the right certificate
C.signed list of certificates a CA has revoked before their expiry
D.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
Answer + AI explanation with Pro
2. Which term means: "Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL"?
Junior
A.HTTPS
B.TLS
C.CAA record
D.OCSP
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.TLS — DNS record specifying which CAs are authorized to issue certificates for a domain
B.TLS — TLS where both client and server present and verify certificates for two-way authentication
C.TLS — Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
D.TLS — signed list of certificates a CA has revoked before their expiry
Answer + AI explanation with Pro
4. What is Certificate Authority (CA)?
Junior
A.forcing peers to negotiate a weaker protocol or cipher than both actually support
B.trusted entity that issues and signs digital certificates binding identities to public keys
C.request containing a public key and identity sent to a CA to obtain a signed certificate
D.latest TLS version with a faster 1-RTT handshake and removal of legacy insecure ciphers
Answer + AI explanation with Pro
5. Which term means: "trusted entity that issues and signs digital certificates binding identities to public keys"?
Junior
A.Certificate Authority (CA)
B.Certificate chain
C.Self-signed certificate
D.TLS 1.3
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.Certificate Authority (CA) — signed list of certificates a CA has revoked before their expiry
B.Certificate Authority (CA) — trusted entity that issues and signs digital certificates binding identities to public keys
C.Certificate Authority (CA) — TLS where both client and server present and verify certificates for two-way authentication
D.Certificate Authority (CA) — request containing a public key and identity sent to a CA to obtain a signed certificate
Answer + AI explanation with Pro
7. What is X.509 certificate?
Junior
A.public append-only logs of issued certificates so mis-issuance can be detected
B.framework of CAs, certificates, and policies for managing public-key encryption and trust
C.standard format for a public-key certificate containing identity, public key, and CA signature
D.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
Answer + AI explanation with Pro
8. Which term means: "standard format for a public-key certificate containing identity, public key, and CA signature"?
Junior
A.Cipher suite
B.TLS
C.Downgrade attack
D.X.509 certificate
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.X.509 certificate — automated protocol (used by Let's Encrypt) for issuing and renewing certificates without manual steps
B.X.509 certificate — certificate signed by its own key rather than a trusted CA, untrusted by default
C.X.509 certificate — standard format for a public-key certificate containing identity, public key, and CA signature
D.X.509 certificate — ordered path from a server's leaf certificate through intermediates up to a trusted root CA
Answer + AI explanation with Pro
10. What is Public Key Infrastructure (PKI)?
Junior
A.forcing peers to negotiate a weaker protocol or cipher than both actually support
B.ordered path from a server's leaf certificate through intermediates up to a trusted root CA
C.standard format for a public-key certificate containing identity, public key, and CA signature
D.framework of CAs, certificates, and policies for managing public-key encryption and trust
Answer + AI explanation with Pro
11. Which term means: "framework of CAs, certificates, and policies for managing public-key encryption and trust"?
Junior
A.Public Key Infrastructure (PKI)
B.X.509 certificate
C.Certificate Signing Request (CSR)
D.OCSP stapling
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.Public Key Infrastructure (PKI) — Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
B.Public Key Infrastructure (PKI) — framework of CAs, certificates, and policies for managing public-key encryption and trust
C.Public Key Infrastructure (PKI) — certificate signed by its own key rather than a trusted CA, untrusted by default
D.Public Key Infrastructure (PKI) — HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections
Answer + AI explanation with Pro
13. What is HTTPS?
Junior
A.standard format for a public-key certificate containing identity, public key, and CA signature
B.forcing peers to negotiate a weaker protocol or cipher than both actually support
C.HTTP layered over TLS to provide encrypted, authenticated web communication
D.DNS record specifying which CAs are authorized to issue certificates for a domain
Answer + AI explanation with Pro
14. Which term means: "HTTP layered over TLS to provide encrypted, authenticated web communication"?
Junior
A.HTTPS
B.OCSP
C.Cipher suite
D.TLS 1.3
Answer + AI explanation with Pro
15. Which statement is correct?
Junior
A.HTTPS — Server Name Indication, a TLS extension letting a client specify the hostname so a server can present the right certificate
B.HTTPS — HTTP layered over TLS to provide encrypted, authenticated web communication
C.HTTPS — TLS where both client and server present and verify certificates for two-way authentication
D.HTTPS — framework of CAs, certificates, and policies for managing public-key encryption and trust
Answer + AI explanation with Pro
16. What is TLS handshake?
Mid
A.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
B.negotiation where client and server agree on a cipher suite, authenticate, and establish session keys
C.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
D.HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections
Answer + AI explanation with Pro
17. Which term means: "negotiation where client and server agree on a cipher suite, authenticate, and establish session keys"?
Mid
A.Certificate Transparency
B.Certificate Signing Request (CSR)
C.TLS handshake
D.Wildcard certificate
Answer + AI explanation with Pro
18. Which statement is correct?
Mid
A.TLS handshake — public append-only logs of issued certificates so mis-issuance can be detected
B.TLS handshake — signed list of certificates a CA has revoked before their expiry
C.TLS handshake — negotiation where client and server agree on a cipher suite, authenticate, and establish session keys
D.TLS handshake — latest TLS version with a faster 1-RTT handshake and removal of legacy insecure ciphers
Answer + AI explanation with Pro
19. What is Certificate chain?
Mid
A.request containing a public key and identity sent to a CA to obtain a signed certificate
B.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
C.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
D.ordered path from a server's leaf certificate through intermediates up to a trusted root CA
Answer + AI explanation with Pro
20. Which term means: "ordered path from a server's leaf certificate through intermediates up to a trusted root CA"?
Mid
A.Certificate chain
B.X.509 certificate
C.Certificate Authority (CA)
D.Certificate Revocation List (CRL)
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.Certificate chain — HTTP layered over TLS to provide encrypted, authenticated web communication
B.Certificate chain — automated protocol (used by Let's Encrypt) for issuing and renewing certificates without manual steps
C.Certificate chain — TLS where both client and server present and verify certificates for two-way authentication
D.Certificate chain — ordered path from a server's leaf certificate through intermediates up to a trusted root CA
Answer + AI explanation with Pro
22. What is Cipher suite?
Mid
A.TLS where both client and server present and verify certificates for two-way authentication
B.HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections
C.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
D.named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session
Answer + AI explanation with Pro
23. Which term means: "named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session"?
Mid
A.HSTS
B.Certificate chain
C.Cipher suite
D.Certificate Revocation List (CRL)
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Cipher suite — trusted entity that issues and signs digital certificates binding identities to public keys
B.Cipher suite — HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections
C.Cipher suite — named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session
D.Cipher suite — negotiation where client and server agree on a cipher suite, authenticate, and establish session keys
Answer + AI explanation with Pro
25. What is Certificate Revocation List (CRL)?
Mid
A.latest TLS version with a faster 1-RTT handshake and removal of legacy insecure ciphers
B.certificate signed by its own key rather than a trusted CA, untrusted by default
C.signed list of certificates a CA has revoked before their expiry
D.request containing a public key and identity sent to a CA to obtain a signed certificate
Answer + AI explanation with Pro
26. Which term means: "signed list of certificates a CA has revoked before their expiry"?
Mid
A.Certificate Revocation List (CRL)
B.ACME protocol
C.OCSP stapling
D.Certificate Authority (CA)
Answer + AI explanation with Pro
27. Which statement is correct?
Mid
A.Certificate Revocation List (CRL) — signed list of certificates a CA has revoked before their expiry
B.Certificate Revocation List (CRL) — request containing a public key and identity sent to a CA to obtain a signed certificate
C.Certificate Revocation List (CRL) — HTTP layered over TLS to provide encrypted, authenticated web communication
D.Certificate Revocation List (CRL) — Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
Answer + AI explanation with Pro
28. What is OCSP?
Mid
A.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
B.Server Name Indication, a TLS extension letting a client specify the hostname so a server can present the right certificate
C.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
D.certificate signed by its own key rather than a trusted CA, untrusted by default
Answer + AI explanation with Pro
29. Which term means: "Online Certificate Status Protocol for checking in real time whether a certificate has been revoked"?
Mid
A.Downgrade attack
B.X.509 certificate
C.Self-signed certificate
D.OCSP
Answer + AI explanation with Pro
30. Which statement is correct?
Mid
A.OCSP — Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
B.OCSP — standard format for a public-key certificate containing identity, public key, and CA signature
C.OCSP — named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session
D.OCSP — Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
Answer + AI explanation with Pro
Showing 30 of 72 Crypto · TLS & PKI questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Crypto · TLS & PKI question come with Pro.