ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A deployment tool downloads a vendor-supplied patch file that is protected with a digital signature. To confirm the file's integrity before installation, which step must the tool perform as part of signature validation?
Hash the downloaded file and compare the result with the hash value obtained by decrypting the signature with the vendor's public key.
Verify that the vendor's X.509 certificate chain and timestamp are valid, assuming integrity if both checks succeed.
Encrypt the entire downloaded file with the vendor's public key and verify that the ciphertext length matches the original signature length.
Compare the file's size and an unsigned checksum published on the vendor's HTTPS web page.
In a public-key-based digital signature, the sender first hashes the original file and encrypts that hash with the sender's private key. The receiver verifies integrity by decrypting the signature with the sender's public key to recover the original hash value, then locally hashing the received file and comparing the two digests. A match proves that no bits were altered in transit. Simply checking certificate validity, file size, or encrypting the file itself does not ensure that the contents have remained unchanged.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a digital signature?
Open an interactive chat with Bash
What is the role of public and private keys in digital signatures?
Open an interactive chat with Bash
What is X.509 in the context of certificates?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .