ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a compliance assessment of a federal agency's document-management system, you learn that several archived policy files may have been modified after their official approval. The system owner wants a safeguard that will make any future tampering immediately evident and discourage unauthorized changes throughout the documents' long-term retention. Which mechanism best meets this need?
Encrypt the files with AES-256 during storage and transmission
Apply a digital signature to each archived document and verify the signature on access or during periodic audits
Implement role-based access control so only authorized users can read or write the archives
Maintain redundant copies of the archives in geographically separate data centers
A digital signature combines a cryptographic hash of the document with the signer's private key, producing a value that can later be verified with the corresponding public key. Because any change to the document alters the underlying hash, the signature verification will fail, immediately revealing unauthorized modifications and thereby deterring tampering. Role-based access control restricts who can access or change files but cannot prove that content remains unchanged. Encrypting with AES-256 without authentication maintains confidentiality, not integrity. Geographic redundancy focuses on availability and does not detect or deter content alteration. Therefore, applying digital signatures to each stored policy file is the most effective approach for preserving long-term integrity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Can you explain how digital signatures detect tampering?
Open an interactive chat with Bash
What is the difference between encryption and digital signatures?
Open an interactive chat with Bash
What is a cryptographic hash and how is it used in compliance mechanisms?
Open an interactive chat with Bash
What is a digital signature?
Open an interactive chat with Bash
How does a cryptographic hash function work in digital signatures?
Open an interactive chat with Bash
Why is encrypting documents with AES-256 not sufficient for integrity protection?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .