Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A cybersecurity team is evaluating different methods to protect sensitive data during transmission across an untrusted network. They need a cryptographic technique that ensures both the confidentiality and integrity of the data, as well as providing authentication of the sender. Which cryptographic concept best fits these requirements?
- AHashing
- BSymmetric-key encryption
- CAsymmetric-key encryption
- DDigital signatures
Show answer & explanationAnswer & explanation
Correct answer: D. Digital signatures
Digital signatures provide authenticity, integrity, and non-repudiation. When combined with asymmetric-key encryption for confidentiality, they fulfill all the stated requirements for secure data transmission.
Why the other options are wrong
- A. Hashing provides integrity checking but does not offer confidentiality, authentication, or non-repudiation.
- B. Symmetric-key encryption provides confidentiality but not built-in integrity, authentication, or non-repudiation.
- C. Asymmetric-key encryption provides confidentiality (encryption) but does not inherently provide sender authentication or integrity without additional mechanisms like digital signatures.
Digital Signature
A mathematical scheme for verifying the authenticity and integrity of digital messages or documents.
- Uses asymmetric cryptography.
- Provides sender authentication, data integrity, and non-repudiation.
- Does not directly provide confidentiality (encryption must be added separately).
Memory trick: Sign, Seal, and Deliver, ensuring it's really from the sender and hasn't changed.