Certified Cloud Security Professional (CCSP)Cloud Data SecurityMedium

A public sector organization is implementing a cloud-based data analytics platform. Due to the highly sensitive nature of the data (e.g., citizen health records), they need to ensure that the data is not only encrypted at rest and in transit but also that the integrity of the data is maintained against unauthorized modifications. Which cryptographic primitive, when used in conjunction with encryption, is primarily responsible for ensuring data integrity?

  1. ASymmetric Encryption
  2. BDigital Signature
  3. CHashing
  4. DAsymmetric Encryption
Show answer & explanation

Correct answer: C. Hashing

Hashing (specifically cryptographic hashing) is primarily used to ensure data integrity. By computing a hash of the data before transmission or storage and reverifying it later, any unauthorized modification to the data will result in a different hash, indicating tampering.

Why the other options are wrong

  • A. Symmetric encryption provides confidentiality (secrecy) but does not inherently guarantee integrity against modification.
  • B. Digital signatures provide authenticity and non-repudiation, and indirectly integrity, but hashing is the underlying primitive for integrity checking.
  • D. Asymmetric encryption provides confidentiality, authenticity, and non-repudiation, but hashing is the direct mechanism for integrity verification.

Cryptographic Hashing

Cryptographic hashing is a mathematical algorithm that maps data of arbitrary size to a fixed-size bit array (hash value or message digest). It is primarily used for ensuring data integrity, as any alteration to the input data will produce a different hash value.

  • Generates a fixed-size output (hash value).
  • One-way function (computationally infeasible to reverse).
  • Collision resistant (hard to find two inputs with same hash).
  • Primarily used for data integrity verification.

Memory trick: Hash: Integrity's Hidden Helper.

More Cloud Data Security questions