ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team receives a critical patch library as a compressed file from a third-party supplier. To satisfy internal policy requiring proof of both integrity and authenticity before integration, which action provides the strongest cryptographic assurance in a single step?
Download the file again over HTTPS and compare byte counts between copies.
Recompute the SHA-256 checksum and compare it with the value on the supplier's website.
Validate the file's detached digital signature using the supplier's published public key.
Perform a vulnerability scan of the library with the latest CVE database.
Verifying the supplier's digital signature first recomputes the file's cryptographic hash and then checks that the hash was signed with the supplier's private key. A successful verification proves the object has not been altered (integrity) and that it was released by the legitimate supplier (authenticity). A simple checksum comparison only confirms integrity, not origin. Re-downloading over HTTPS protects the transfer but cannot detect tampering that occurred before download. Vulnerability scanning assesses code quality but supplies no cryptographic proof of source or integrity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does a digital signature verify both integrity and authenticity?
Open an interactive chat with Bash
What is the role of public and private keys in digital signatures?
Open an interactive chat with Bash
Why is checking a hash alone insufficient for authenticity?
Open an interactive chat with Bash
What is a digital signature, and how does it prove authenticity?
Open an interactive chat with Bash
What role does a public key play in validating a signature?
Open an interactive chat with Bash
How does a SHA-256 checksum differ from cryptographic validation with digital signatures?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .