Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security architect is designing a system that requires ensuring data not only remains confidential but also that its origin can be verified and that the sender cannot later deny having sent it. Which cryptographic primitive is essential for achieving both data origin authentication and non-repudiation?

  1. AHashing
  2. BKey Exchange
  3. CDigital Signatures
  4. DSymmetric Encryption
Show answer & explanation

Correct answer: C. Digital Signatures

Digital signatures use asymmetric cryptography to provide data integrity, data origin authentication, and non-repudiation. The sender uses their private key to sign a hash of the message, and the recipient uses the sender's public key to verify the signature, proving the sender's identity and that the message hasn't been altered.

Why the other options are wrong

  • A. Hashing ensures integrity (detects alteration) but not origin authentication or non-repudiation.
  • B. Key Exchange establishes shared keys but doesn't inherently provide origin authentication or non-repudiation for messages.
  • D. Symmetric Encryption ensures confidentiality but not origin authentication or non-repudiation.

Digital Signature

A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authentication), that the sender cannot deny having sent the message (non-repudiation), and that the message was not altered in transit (integrity).

  • Uses asymmetric cryptography (public/private key pairs).
  • Provides data integrity, data origin authentication, and non-repudiation.
  • Often involves hashing the message first, then encrypting the hash with the sender's private key.
  • Verifier uses sender's public key to decrypt the hash and compare it to a newly computed hash of the message.

Memory trick: Crypto tools secure data; signatures prove who sent it and that it's untouched.

More Security Concepts questions