ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a secure‐update project, you must ensure that desktop clients can verify both the origin and the untampered state of each new executable they download from the company's server. Which control is the most effective way to meet this requirement?
Digitally sign each release with a trusted code-signing certificate and have clients verify the signature before execution
Publish a separate SHA-256 checksum that users can compare after downloading
Apply code obfuscation to make the binary harder to analyze
Distribute the files over HTTPS to prevent interception during download
Code signing applies a digital signature-created with the publisher's private key-to the hash of an executable. When clients download the file, their systems use the corresponding public certificate to validate the signature. If the file has been altered or the signer is untrusted, verification fails, preventing execution. Transport encryption (e.g., HTTPS) protects data only while in transit, hashes published on a web page do not prove who created the code, and obfuscation merely complicates reverse engineering without assuring integrity or authenticity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is code signing and how does it ensure the integrity of an executable?
Open an interactive chat with Bash
How is verifying a SHA-256 checksum different from code signing?
Open an interactive chat with Bash
Why doesn’t HTTPS alone guarantee the authenticity of executable files?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .