ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your organization publishes firmware images to IoT devices over the Internet. To protect the images in transit, engineers already compute a SHA-256 hash that devices verify before installation. Compliance now mandates proof that images truly originate from the corporate signing authority, not just that they remain unaltered. Which additional cryptographic property must be implemented to satisfy this requirement?
Authenticity ensured by digitally signing each firmware image with the organization's private key.
Confidentiality provided by encrypting the firmware image with a symmetric algorithm like AES.
Non-repudiation enforced through time-stamped audit logs of every firmware release.
Availability maintained by hosting the firmware on redundant content delivery networks (CDNs).
A hash allows the device to detect any change to the firmware, providing integrity. It does not prove who created the file. To show the code comes from the authorized source, the organization must add authenticity, typically by applying a digital signature with the organization's private key and validating it with the corresponding public key. Encrypting the file would supply confidentiality, redundant distribution addresses availability, and audit logging supports non-repudiation, but none of these alone prove origin. Only authenticity meets the stated requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a digital signature and how does it ensure authenticity?
Open an interactive chat with Bash
What is SHA-256 and why is it used to verify integrity?
Open an interactive chat with Bash
How does the combination of digital signatures and public/private key pairs work?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .