SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium

A financial institution is developing a new online banking application. They require a robust mechanism to ensure the integrity and authenticity of transactions, preventing both accidental alteration and malicious tampering of data during transmission. Which cryptographic control would be most appropriate for this requirement?

  1. ADigital Certificates
  2. BHashing with a Message Authentication Code (MAC)
  3. CSymmetric Encryption
  4. DAsymmetric Encryption
Show answer & explanation

Correct answer: B. Hashing with a Message Authentication Code (MAC)

A Message Authentication Code (MAC) uses a secret key with a cryptographic hash function to provide both data integrity (detects alterations) and authenticity (proves sender's knowledge of the key), precisely meeting the requirement.

Why the other options are wrong

  • A. Digital certificates bind a public key to an identity; they do not directly provide transaction integrity or authenticity on their own but are part of a digital signature scheme.
  • C. Symmetric encryption provides confidentiality but not inherent integrity or authenticity.
  • D. Asymmetric encryption provides confidentiality and can be used for digital signatures (authenticity/integrity), but a MAC is more direct for integrity and authenticity with a shared secret.

Message Authentication Code (MAC)

A short piece of information used to authenticate a message and provide integrity and authenticity assurances for data. A MAC algorithm, sometimes called a keyed hash function, accepts a secret key and an arbitrary-length message as input and outputs a MAC.

  • Provides data integrity and authenticity.
  • Uses a secret key.
  • Prevents both accidental and malicious alteration of data.

Memory trick: Cryptography has many tools, pick the right one for your rules.

More Systems and Application Security questions