A system administrator downloads a vendor patch package and a separate checksum file. After the download completes, the administrator runs a command that produces a SHA-256 value for the package and compares it to the vendor's published value. Which cryptographic primitive is being used for the comparison?
Hashing creates a fixed-length digest from data so the receiver can compare values and detect changes. In this scenario, the administrator is generating a SHA-256 result and comparing it to the vendor's published value to confirm the package has not changed. That use case is about integrity verification rather than encryption or identity proof.
Why this answer
The administrator is using SHA-256 to compute a fixed-length digest of the downloaded package and comparing it to the vendor's published checksum. This is a classic application of a cryptographic hash function (hashing), which produces a unique, irreversible fingerprint of data. The comparison verifies integrity—ensuring the package has not been altered during transit—but does not provide authentication or non-repudiation.
Exam trap
The trap here is that candidates confuse integrity verification via hashing with authentication provided by digital signatures, especially when the question mentions a 'vendor' and 'comparison'—leading them to incorrectly choose digital signatures (Option C) even though no signature verification is performed.
How to eliminate wrong answers
Option B (Symmetric encryption) is wrong because it uses a shared secret key to encrypt and decrypt data, not to produce a fixed-length digest for integrity verification. Option C (Digital signatures) is wrong because they combine hashing with asymmetric encryption to provide authentication and non-repudiation, but the scenario only describes comparing a hash value, not verifying a signature with a public key. Option D (Asymmetric encryption) is wrong because it uses a public/private key pair for encryption or key exchange, not for generating a checksum to compare against a published value.