200-201 Deterministic Practice Question
An organization wants to ensure the integrity of software updates downloaded from its vendor's website. The vendor provides a hash value for each update. Which TWO properties of hashing algorithms make them suitable for integrity verification? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse hashing with encryption or MACs — candidates pick 'reversible' or 'requires a secret key' because they conflate hash functions with symmetric ciphers or HMAC, when hashing is one-way and keyless.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The same input always produces the same hash.
Option A is correct because hashing is deterministic: for a given algorithm, the same input always produces the same hash value, so a recipient can recompute the hash of a downloaded update and compare it to the vendor-published hash to verify integrity. Option B is correct because of the avalanche effect, where even a one-bit change in the input produces a drastically different hash, making any tampering with the update immediately detectable. Option C is incorrect because hashing is a one-way function and cannot be reversed to recover the original data. Option D is incorrect because, while true for a given algorithm, fixed output length is not the property that enables integrity verification of the update content. Option E is incorrect because hashing does not require a secret key; keyed constructions like HMAC use a key, but plain hashing algorithms do not.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The same input always produces the same hash.
Why this is correct
Deterministic output lets the administrator recompute the digest from the downloaded file and compare it against the vendor's published value; any alteration to the update, however small, yields a different hash, exposing tampering. This satisfies the integrity-verification requirement without needing the vendor's private key or a shared secret.
- ✓
A small change in input results in a significantly different hash.
Why this is correct
The avalanche effect: altering even one bit of input produces a drastically different digest, so any tampering with a downloaded update yields a mismatched hash, exposing the modification during comparison against the vendor's published value.
- ✗
The hash can be reversed to obtain the original data.
Why it's wrong here
Reversibility would defeat integrity verification entirely; hashing is deliberately one-way so the original data cannot be recovered from the digest. Reversible transformation describes encryption, which is the right choice when confidentiality of the update contents is the requirement rather than tamper detection.
- ✗
The hash output is always the same length for a given algorithm.
Why it's wrong here
Fixed-length output aids comparison and storage but does not detect tampering; an attacker can alter the update and recompute a same-length digest. This property matters when parsing or storing digests of differing input sizes, not for the collision resistance and avalanche effect that integrity verification demands.
- ✗
Hashing requires a secret key to generate the hash.
Why it's wrong here
Hashing is unkeyed; anyone can compute a digest, so a secret key is not required. Keyed generation describes HMAC or a MAC, which would be chosen when both integrity and authenticity between parties sharing a key are needed, not for verifying a vendor's published hash.
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.