ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A cloud security architect must ensure that each tenant's data stored in a multi-tenant SaaS platform can be checked for unauthorized modification at any time without requiring the platform operator to decrypt the data. Which of the following approaches best satisfies this requirement while minimizing computational overhead?
Append an MD5 checksum with a static salt to every file and periodically recalculate the value for comparison.
Calculate a SHA-256 digest of each object at upload and store the hash in a separate, tamper-evident metadata repository for later comparison.
Encrypt the files with AES-256 in Galois/Counter Mode so the authentication tag can be used to confirm integrity when needed.
Apply reversible Base64 encoding to each file and verify integrity by decoding and comparing sizes.
Storing a strong cryptographic hash such as SHA-256 for every object in a protected, tamper-evident metadata repository allows the platform to recalculate the hash on demand and compare it to the stored value to verify integrity. Because hashing is a one-way function, no decryption is needed to detect changes. MD5 is deprecated due to proven collision attacks, and adding a static salt does not restore adequate security. AES-256 in GCM mode provides both confidentiality and integrity, but the authentication tag is verified only during decryption, which violates the without decrypting constraint. Base64 is merely an encoding scheme, not a cryptographic mechanism, and cannot detect manipulation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SHA-256 and why is it suitable for ensuring data integrity?
Open an interactive chat with Bash
What is a tamper-evident metadata repository and how does it protect stored hashes?
Open an interactive chat with Bash
Why is MD5 deprecated, and why is a static salt insufficient for security?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .