ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A vendor distributes quarterly firmware updates to customers' industrial controllers over the Internet. The update files must stay confidential while in transit, and customers must be able to confirm that each file is authentic and unaltered before installing it. Which approach BEST satisfies all of these security requirements?
Compress the firmware and include a SHA-256 checksum file for customers to compare before installation
Encrypt the firmware with AES-256 and apply a digital signature using the vendor's private signing key
Encrypt the firmware using the vendor's private key so customers can decrypt it with the public key
Encrypt the firmware with AES-256 and email the symmetric key to each customer
Encrypting the firmware with a strong symmetric algorithm such as AES-256 keeps the contents confidential during transit because only parties that possess the secret key can decrypt it. Adding a digital signature created with the vendor's private key over a hash of the encrypted file allows recipients to verify both integrity (the file has not changed) and authenticity (the vendor is the signer) and also supports non-repudiation. The other options fall short: a checksum alone offers no confidentiality; sending a symmetric key by unprotected e-mail exposes the key; and encrypting with a private key offers no confidentiality because anyone with the widely distributed public key could decrypt the file.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is AES-256 encryption suitable for securing firmware updates in transit?
Open an interactive chat with Bash
What is a digital signature, and how does it verify authenticity and integrity?
Open an interactive chat with Bash
Why is encrypting with a private key not suitable for ensuring the confidentiality of firmware updates?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .