Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

Which cryptographic technique uses a public and private key pair to provide non-repudiation?

⚠ Common exam trap

200-201 often tests the difference between integrity (hashing), confidentiality (encryption), authentication (certificates), and non-repudiation (digital signatures) — candidates confuse digital certificates with digital signatures, but only the signature uses the private key to prove origin.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Digital signature

A digital signature is created by hashing the message and encrypting that hash with the sender's private key. Anyone can verify it using the sender's public key, and because only the sender possesses the private key, the sender cannot later deny having signed it — this is non-repudiation. Symmetric encryption, certificates, and hashing alone do not provide that property.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Digital signature

    Why this is correct

    A digital signature is generated using the sender's private key, which only they possess, so they cannot later deny creating it. Verification with the corresponding public key provides non-repudiation, the specific property the stem requires.

  • ✗

    Symmetric encryption

    Why it's wrong here

    Symmetric encryption uses one shared secret key for both encryption and decryption, so either party could have produced the ciphertext. Non-repudiation requires an asymmetric private key held by one signer, which symmetric algorithms cannot supply.

  • ✗

    Digital certificate

    Why it's wrong here

    A digital certificate binds an identity to a public key via a Certificate Authority's signature; it does not itself generate the key pair or produce the signature that proves origin. It is tempting because certificates underpin PKI and Microsoft Entra ID authentication, yet they are the correct choice when validating identity ownership, not when the question asks which technique delivers non-repudiation.

  • ✗

    Hashing

    Why it's wrong here

    Hashing produces a one-way fixed-length digest for integrity checking; it uses no key pair and cannot bind an identity to a message. Asymmetric signing with a private key is what delivers non-repudiation, which hashing alone cannot provide.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.