ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A DevOps engineer needs to publish daily initialization scripts to an Amazon S3 bucket for automated EC2 deployments used by multiple teams. Management requires that anyone who downloads a script can verify it has not been modified in transit and that it truly originated from the central automation account, enabling accountability if a faulty script is distributed. Which approach BEST meets these integrity and authenticity requirements?
Compress the scripts using gzip to reduce size before uploading to the S3 bucket
Digitally sign each script with an AWS KMS-hosted RSA private key and distribute the matching public key for signature verification
Include a SHA-256 checksum file alongside every script so users can recompute and compare the hash before execution
Encrypt each script with an AWS KMS symmetric CMK before upload and share the key with all consuming teams
A digital signature created with the automation account's private key lets recipients use the corresponding public key to verify both that the script's contents remain unchanged (integrity) and that only the key holder could have produced it (authenticity and non-repudiation). A standalone SHA-256 checksum detects alteration but cannot prove authorship. Encrypting with a shared symmetric key provides confidentiality but not verifiable origin, and gzip compression offers neither integrity nor authenticity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are digital signatures, and how do they ensure integrity and authenticity?
Open an interactive chat with Bash
What is AWS KMS-hosted RSA private key, and why is it suitable for signing scripts?
Open an interactive chat with Bash
What is the difference between encryption and digital signatures when securing scripts?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .