Which cryptographic technique uses a public and private key pair to provide non-repudiation?
A digital signature is generated using the sender's private key, which only they possess, so they cannot later deny creating it. Verification with the corresponding public key provides non-repudiation, the specific property the stem requires.
Why this answer
A digital signature is created by hashing the message and encrypting that hash with the sender's private key. Anyone can verify it using the sender's public key, and because only the sender possesses the private key, the sender cannot later deny having signed it — this is non-repudiation. Symmetric encryption, certificates, and hashing alone do not provide that property.
Exam trap
200-201 often tests the difference between integrity (hashing), confidentiality (encryption), authentication (certificates), and non-repudiation (digital signatures) — candidates confuse digital certificates with digital signatures, but only the signature uses the private key to prove origin.
How to eliminate wrong answers
Option B is wrong because symmetric encryption uses a single shared secret key for both encryption and decryption, so either party could have produced the ciphertext — there is no proof of origin and thus no non-repudiation. Option C is wrong because a digital certificate binds a public key to an identity via a CA's signature; it enables authentication and trust but does not itself sign the message or provide non-repudiation of the message content. Option D is wrong because hashing alone provides integrity (a fixed-length digest) but no key or identity binding — anyone can compute the same hash, so it cannot prove who sent the data.