CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is designing a new enterprise application that requires high assurance of data integrity and authenticity for critical transactions. The solution must ensure that any modification to the transaction data, even a single bit, is immediately detectable and attributable to a specific entity. Which cryptographic primitive would be MOST suitable for this requirement?
- AKey Exchange
- BDigital Signature
- CSymmetric Encryption
- DHashing
Show answer & explanationAnswer & explanation
Correct answer: B. Digital Signature
A digital signature provides both data integrity (detecting modifications) and authenticity (attributing the data to a specific signer). It uses asymmetric cryptography, where the sender signs a hash of the data with their private key, and the receiver verifies it with the sender's public key. Hashing alone only provides integrity, not authenticity.
Why the other options are wrong
- A. Key exchange protocols are used to securely establish shared secret keys, not for data integrity or authenticity of transactions.
- C. Symmetric encryption provides confidentiality but not integrity or authenticity on its own.
- D. Hashing provides data integrity by creating a fixed-size output, but it does not provide authenticity or non-repudiation.
Digital Signature
A digital signature is a cryptographic mechanism that provides data integrity, authenticity, and non-repudiation for digital messages or documents.
- Uses asymmetric cryptography (private key for signing, public key for verification).
- Ensures data has not been altered since it was signed.
- Proves the identity of the signer and prevents them from denying their signature.
Memory trick: Confidentiality hides, integrity checks, authenticity proves.