CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a secure software supply chain for a critical aerospace system. The design requires ensuring the integrity and authenticity of all software components, libraries, and binaries throughout the development, build, and deployment pipelines. Any unauthorized modification or tampering at any stage must be detected and prevented. Which security control or process is most effective for achieving this end-to-end integrity and authenticity?

  1. AUtilizing cryptographic signing and verification for all artifacts.
  2. BEnforcing code reviews for all pull requests before merging.
  3. CImplementing Static Application Security Testing (SAST) in the CI/CD pipeline.
  4. DDeploying Web Application Firewalls (WAFs) to protect deployed applications.
Show answer & explanation

Correct answer: A. Utilizing cryptographic signing and verification for all artifacts.

Cryptographic signing and verification (e.g., using digital signatures with public/private key pairs) is the most effective method for ensuring the integrity and authenticity of software artifacts throughout the supply chain. Each component is signed by its creator, and its signature is verified at every stage. This process detects any unauthorized modification or tampering, as a tampered artifact would have an invalid signature.

Why the other options are wrong

  • B. Code reviews help improve code quality and identify logical vulnerabilities but do not cryptographically guarantee the integrity of compiled artifacts or detect tampering after the code is merged.
  • C. SAST identifies vulnerabilities in source code but does not guarantee the integrity or authenticity of compiled binaries or third-party libraries against tampering.
  • D. WAFs protect deployed applications from web-based attacks but do not secure the integrity or authenticity of the software supply chain itself during development or deployment.

Cryptographic Signing & Verification

The process of using digital signatures to ensure the authenticity and integrity of data or software artifacts, where a private key signs and a public key verifies.

  • Guarantees that data has not been altered since it was signed.
  • Verifies the identity of the signer (authenticity).
  • Essential for securing software supply chains and ensuring trusted components.

Memory trick: Securing the supply chain is like putting a 'tamper-proof seal' on every package and checking it at every stop.

More Security Architecture questions