ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During your build pipeline you automatically sign a Windows kernel-mode driver with an Authenticode certificate. You want users to be able to verify the signature even after the certificate's validity period has ended. Which additional step should you add to the signing process to best meet this goal?
Compress the driver binary with a newer SHA-256 hash algorithm before signing.
Publish the signer's public certificate to an internal LDAP directory after release.
Request a trusted timestamp from a Time Stamping Authority when generating the signature.
Encrypt the driver package with the same private key used for signing.
Adding a trusted timestamp at the moment the driver is signed embeds the date and time of signing into the signature and links it to a Time Stamping Authority's certificate. Because the signature is considered valid if the certificate was valid at the time of signing, timestamping allows the integrity and authenticity of the code to be verified long after the signer's certificate has expired or been renewed. Simply hashing, encrypting, or publishing the certificate elsewhere does not provide this lasting proof; without a timestamp the operating system will treat the signature as invalid once the signing certificate's validity period ends.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Time Stamping Authority (TSA)?
Open an interactive chat with Bash
Why does timestamping ensure validity after a certificate expires?
Open an interactive chat with Bash
How does Authenticode work for signing Windows binaries?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .