ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a build pipeline, you need to confirm that a 50 KB JSON configuration file checked into source control has not been tampered with before it is packaged into the container image. Which approach provides the most reliable, automated proof of the file's integrity?
Store the file on a RAID 1 volume to guarantee bit-level consistency.
Compute a SHA-256 digest of the file during each run and compare it to the previously stored baseline hash.
Compress the file with gzip and compare the resulting archive size to yesterday's build.
Encrypt the file with AES-256 and verify that decryption succeeds before packaging.
A cryptographic hash such as SHA-256 produces a fixed-length digest that changes unpredictably if even one bit of the file is altered. Storing a baseline digest and recomputing it during each build allows an automated comparison that will immediately reveal unauthorized modification. Encrypting the file only hides its contents and does not detect changes; successful decryption simply proves the key was correct. RAID 1 protects against disk failure, not deliberate or accidental file edits. Comparing compressed file sizes is unreliable because different content can produce the same size, and gzip does not provide integrity assurance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SHA-256 and why is it used for file integrity?
Open an interactive chat with Bash
Why is encryption like AES-256 not appropriate for detecting file tampering?
Open an interactive chat with Bash
What are the limitations of RAID 1 and gzip for file integrity verification?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .