CompTIA Cloud+ (CV0-004)SecurityEasy
A financial institution is migrating its core banking application to a cloud environment. The security team requires a mechanism to ensure that the integrity of data at rest is maintained and that any unauthorized modification is immediately detectable. Which of the following cryptographic techniques would best address this requirement?
- ASteganography
- BHashing
- CSymmetric encryption
- DAsymmetric encryption
Show answer & explanationAnswer & explanation
Correct answer: B. Hashing
Hashing provides a fixed-size unique output (hash value) for any given input. If the data is modified, even slightly, the hash value will change, immediately indicating a data integrity compromise. It does not encrypt the data, but rather validates its integrity.
Why the other options are wrong
- A. Steganography is about hiding data, not verifying its integrity.
- C. Symmetric encryption provides confidentiality, not integrity verification directly.
- D. Asymmetric encryption provides confidentiality and authenticity (via digital signatures), but not integrity verification of data at rest on its own.
Hashing for Integrity
Hashing is a cryptographic function that takes an input (or 'message') and returns a fixed-size alphanumeric string, which is called the 'hash value' or 'message digest'. It's primarily used to verify data integrity.
- One-way function: difficult to reverse.
- Fixed-size output regardless of input size.
- Small change in input leads to large change in output (avalanche effect).
- Used for data integrity verification, password storage, and digital signatures.
Memory trick: Hash values are like digital fingerprints; any change to the data changes the print.