200-201 Security Concepts Practice Question
A security administrator needs to verify that a downloaded file has not been altered during transit. Which cryptographic technique should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashing
Hashing produces a fixed-size hash that changes if the file is modified, allowing integrity verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Public key encryption
Why it's wrong here
Public key encryption provides confidentiality by encrypting with the recipient's public key; it does not by itself prove the file is unaltered. A cryptographic hash compared against the published digest detects modification. Public key encryption suits protecting data in transit or at rest for a specific recipient.
- ✗
Symmetric encryption
Why it's wrong here
Symmetric encryption uses one shared key for both encryption and decryption, so it provides confidentiality but produces no separate value that verifies integrity against the original. A hash such as SHA-256 compared with the publisher's digest detects alteration. Symmetric encryption suits bulk data-at-rest protection where both parties already share the key.
- ✓
Hashing
Why this is correct
Hashing produces a fixed-length digest from file contents; recomputing it and comparing against the published value reveals any alteration, satisfying the stem's integrity-verification constraint. Encryption provides confidentiality and digital signatures provide authenticity, neither directly detecting transit modification.
- ✗
Digital signature
Why it's wrong here
A digital signature verifies authenticity and non-repudiation via asymmetric cryptography, but it does not directly confirm that a file remained unaltered during transit unless the signer’s public key is already trusted and the signature was applied before download. The stem asks solely for integrity verification of a downloaded file, which a hash function (e.g., SHA-256) achieves by comparing a pre-computed digest against a freshly computed one. This option is tempting because digital signatures do include a hash, but their primary purpose is to authenticate the signer’s identity and prove origin, making them correct when the requirement is to validate the source rather than just detect transit tampering.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.