200-201 Security Concepts Practice Question
An organization wants to ensure that a received email genuinely came from the claimed sender and has not been altered. Which cryptographic mechanism provides both authentication and integrity?
⚠ Common exam trap
Cisco often tests the distinction between a mechanism (digital signature) and the supporting infrastructure (PKI), leading candidates to mistakenly select PKI because they associate it with certificates and authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Digital signature
A digital signature uses the sender's private key to sign the message, and the recipient verifies it with the sender's public key. This process provides authentication (proving the sender's identity) and integrity (detecting any alteration) because any change to the message invalidates the signature. Hash functions alone provide integrity but not authentication, while PKI is the infrastructure that supports digital signatures but is not the mechanism itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Digital signature
Why this is correct
A digital signature is created with the sender's private key and verified with their public key, so successful verification proves origin and confirms the message was not altered in transit. This delivers both authentication and integrity, matching the stem's requirements.
- ✗
Hash function
Why it's wrong here
A hash function alone detects alteration but uses no key, so anyone can recompute it; it cannot authenticate the sender. It is tempting because hashing underpins integrity checking, and would be correct when the requirement is only to verify that data has not changed.
- ✗
Public key infrastructure (PKI)
Why it's wrong here
PKI is the framework of certificates, CAs and revocation that issues and validates keys; it does not itself sign or verify a message. It is tempting because S/MIME email authentication depends on it, and PKI would be the right answer when asked how trust in public keys is established.
- ✗
Symmetric encryption
Why it's wrong here
Symmetric encryption uses one shared secret key for both parties, so it cannot prove origin to a third party and provides confidentiality rather than sender authentication. It is tempting because it does protect integrity via MACs, and would suit bulk data encryption where both ends already share the key.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.