CompTIA Security+ (SY0-701)General Security ConceptsHard

A user sends a contract document to a business partner and wants the partner to be able to verify both that the document came from the user and that it was not altered in transit. The user creates a hash of the document and encrypts that hash using their own private key before sending it along with the document. What has the user created?

  1. AA certificate signing request
  2. BA symmetric session key
  3. CA message authentication code using a shared secret
  4. DA digital signature
Show answer & explanation

Correct answer: D. A digital signature

Encrypting a hash of the document with the sender's private key creates a digital signature; the recipient can decrypt it with the sender's public key and compare it to a freshly computed hash to verify authenticity and integrity.

Why the other options are wrong

  • A. A certificate signing request is submitted to a CA to obtain a certificate, unrelated to signing a document.
  • B. A symmetric session key would be a shared secret for encrypting data, not for signing a hash with a private key.
  • C. A MAC uses a shared symmetric key, not an asymmetric private key, and doesn't provide non-repudiation.

Digital Signature

A cryptographic mechanism where a hash of data is encrypted with the sender's private key to provide authenticity, integrity, and non-repudiation.

  • Uses sender's private key to sign, public key to verify
  • Provides non-repudiation unlike a simple MAC
  • Common in code signing and secure email (S/MIME)

Memory trick: Sign with private, verify with public — proof it's really you.

More General Security Concepts questions