🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company pushes firmware updates to hundreds of field devices through a public content-delivery network that offers no built-in authentication. Security policy states that every device must be able to confirm that an update originated from headquarters and was not modified in transit, while still allowing anyone to download the file. Which approach BEST meets this requirement?

  • Require each device to download updates through an SSH tunnel established to headquarters.

  • Publish an MD5 checksum of every package so devices can compare the value before installation.

  • Encrypt each package with AES-256 and distribute the symmetric key to devices during provisioning.

  • Sign each firmware package with the organization's private key and have devices verify the signature using the corresponding public certificate.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot