CompTIA Security+ (SY0-701)General Security ConceptsHard
A user sends a contract document to a business partner and wants the partner to be able to verify both that the document came from the user and that it was not altered in transit. The user creates a hash of the document and encrypts that hash using their own private key before sending it along with the document. What has the user created?
- AA certificate signing request
- BA symmetric session key
- CA message authentication code using a shared secret
- DA digital signature
Show answer & explanationAnswer & explanation
Correct answer: D. A digital signature
Encrypting a hash of the document with the sender's private key creates a digital signature; the recipient can decrypt it with the sender's public key and compare it to a freshly computed hash to verify authenticity and integrity.
Why the other options are wrong
- A. A certificate signing request is submitted to a CA to obtain a certificate, unrelated to signing a document.
- B. A symmetric session key would be a shared secret for encrypting data, not for signing a hash with a private key.
- C. A MAC uses a shared symmetric key, not an asymmetric private key, and doesn't provide non-repudiation.
Digital Signature
A cryptographic mechanism where a hash of data is encrypted with the sender's private key to provide authenticity, integrity, and non-repudiation.
- Uses sender's private key to sign, public key to verify
- Provides non-repudiation unlike a simple MAC
- Common in code signing and secure email (S/MIME)
Memory trick: Sign with private, verify with public — proof it's really you.