CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud security architect is tasked with ensuring the integrity of data at rest in a cloud object storage service. The data consists of critical audit logs and financial records that must not be altered without detection. Which cryptographic technique is most suitable for verifying that the data has not been tampered with after it has been stored?
- AAsymmetric Encryption
- BDigital Signatures
- CHashing
- DSymmetric Encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Hashing
Hashing generates a fixed-size string of characters from any input data. Any change, no matter how small, to the original data will result in a completely different hash value, making it an excellent method for detecting data tampering.
Why the other options are wrong
- A. Asymmetric encryption provides confidentiality, authentication, and non-repudiation, but its primary function isn't data integrity detection for stored data.
- B. Digital signatures provide authentication, non-repudiation, and integrity, but hashing is the direct mechanism for integrity verification of the data itself, often a component of digital signatures.
- D. Symmetric encryption provides confidentiality, not integrity. It secures data from unauthorized viewing.
Hashing for Integrity
A cryptographic process that transforms data into a fixed-size string of characters, a 'hash value' or 'message digest.' Any change to the original data results in a different hash value.
- One-way function; impossible to reverse.
- Used to detect data tampering.
- Common algorithms include SHA-256, MD5 (though MD5 is less secure for collision resistance).
Memory trick: Hashes Hide Hidden Humiliations for Honest Handling.