200-201 Security Concepts Practice Question
A security analyst needs to verify that a downloaded software update has not been tampered with. The update's publisher provides a file containing a hash value. Which process should the analyst use to verify integrity?
⚠ Common exam trap
Cisco often tests the distinction between integrity (hash comparison) and authenticity (digital signatures), leading candidates to mistakenly choose digital signature verification when the question only asks about integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compute the file's hash and compare it with the provided hash
Verifying file integrity involves computing a cryptographic hash (e.g., SHA-256) of the downloaded file and comparing it to the hash provided by the publisher. If the hashes match, the file has not been altered; any tampering would produce a different hash value. This is a standard integrity check, not a confidentiality or authentication mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Decrypt the file using the publisher's public key
Why it's wrong here
Public-key decryption applies to data encrypted with the matching private key, which is not how a hash file is produced. It is the right choice for reading a confidential message sent to the key owner, not for confirming a download matches the publisher's published hash.
- ✗
Use a digital signature to sign the file
Why it's wrong here
Signing the file creates a signature; it does not compare the publisher's supplied hash against a locally computed one, so tampering goes undetected. Digital signatures suit verifying authenticity and origin when the publisher signs and the analyst holds the public key, not integrity checking against a provided hash value.
- ✓
Compute the file's hash and compare it with the provided hash
Why this is correct
Hashing is deterministic, so the analyst recomputes the digest of the downloaded file using the same algorithm and compares it against the publisher's supplied value; any mismatch proves the file was altered in transit or storage.
- ✗
Encrypt the file using the publisher's private key
Why it's wrong here
Encrypting with a private key produces a signature, not a hash comparison, and the analyst lacks that private key anyway. It is the right choice for the publisher proving authenticity via a digital signature, not for verifying integrity against a supplied hash value.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.