CompTIA Cloud+ (CV0-004)SecurityHard
A financial institution is migrating its core banking application to a cloud environment. Due to stringent regulatory requirements, the application must demonstrate data integrity and non-repudiation for all transactions. Which cryptographic mechanism, when applied to transaction logs, would best satisfy these requirements?
- AHashing
- BAsymmetric Encryption
- CDigital Signatures
- DSymmetric Encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Digital Signatures
Digital signatures provide both data integrity (by detecting any alteration of the signed data) and non-repudiation (by proving the origin of the signed data and preventing the sender from denying their signature). This directly meets the requirements for financial transactions where integrity and non-repudiation are critical.
Why the other options are wrong
- A. Hashing provides data integrity (detecting changes) but does not provide non-repudiation (it doesn't prove who created the hash).
- B. Asymmetric encryption can provide confidentiality or authentication, but a digital signature (which uses asymmetric cryptography) is the specific mechanism for integrity and non-repudiation.
- D. Symmetric encryption provides confidentiality, but not integrity or non-repudiation on its own.
Digital Signature
A cryptographic mechanism that uses asymmetric cryptography to verify the authenticity and integrity of a digital message or document, providing non-repudiation.
- Uses asymmetric cryptography (public/private key pair)
- Ensures data integrity
- Provides non-repudiation (proof of origin)
Memory trick: Digital Signatures: the unbreakable promise for data integrity and non-repudiation.