ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization distributes container images through an internal registry. Each image is digitally signed by computing a SHA-256 digest of the tarball and encrypting that digest with the registry's RSA private key. To verify a freshly pulled image, what is the first cryptographic operation the deployment server should perform?
Download the current certificate revocation list for the registry's certificate before performing any cryptographic processing.
Compute a new SHA-256 hash of the image and then encrypt that hash with the registry's public key.
Encrypt the downloaded image with the deployment server's own private key and return it to the registry for confirmation.
Decrypt the attached signature with the registry's public key to obtain the signer's SHA-256 digest of the image.
Digital signature verification starts by recovering the original message digest that the signer encrypted with its private key. The verifier therefore applies the signer's public key to the attached signature. This decryption step yields the hash value that the signer originally generated. Only after the digest is recovered does the verifier independently hash the received image and compare the two digests. Encrypting the image, generating a new signature before comparison, or checking revocation lists are useful but are not the initial cryptographic act needed to validate integrity and provide non-repudiation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a SHA-256 digest?
Open an interactive chat with Bash
What is the role of RSA public and private keys in digital signatures?
Open an interactive chat with Bash
What is a Certificate Revocation List (CRL) and its function in cryptographic processes?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .