GSEC Cryptography Practice Question
A junior administrator is asked to verify the integrity of a downloaded Linux distribution ISO before installing it on a production server. The vendor publishes a SHA-256 checksum and a detached PGP signature. Which action BEST confirms both that the file is intact and that it genuinely originated from the vendor?
⚠ Common exam trap
The trap here is believing that matching a published checksum proves the file came from the vendor, when the checksum itself could have been altered alongside the file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Import the vendor's public key, verify the detached signature against the ISO, and confirm the signature is valid.
A valid detached PGP signature verified with the vendor's trusted public key simultaneously proves that the file content is unchanged and that it was signed by the vendor's private key. The hash comparison alone provides integrity but not origin, and encryption or antivirus scanning addresses entirely different concerns. The public key must be obtained and validated through a trusted channel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Import the vendor's public key, verify the detached signature against the ISO, and confirm the signature is valid.
Why this is correct
Verifying the detached PGP signature with the vendor's public key confirms both integrity and origin: a valid signature proves the file was signed by the holder of the corresponding private key and that the content has not changed since signing. This single verification satisfies both requirements. The administrator must first obtain and trust the vendor's public key through an out-of-band channel to avoid a substituted key.
- ✗
Run the ISO through an antivirus scanner and confirm no malware is detected.
Why it's wrong here
An antivirus scan checks for known malicious content but does not verify a cryptographic hash or signature, so it cannot confirm integrity in the cryptographic sense or establish origin. A tampered file with no known malware signature would pass. This approach also depends on signature databases that may lag behind new threats, making it unsuitable as the primary integrity and authenticity check.
- ✗
Compute the SHA-256 hash of the ISO and compare it to the published checksum only.
Why it's wrong here
Comparing the computed SHA-256 hash to the published value detects accidental corruption and verifies integrity, but it does not prove origin. If an attacker can alter the ISO, they can also alter the published checksum on the same compromised site. The hash comparison alone therefore cannot establish that the file genuinely came from the vendor, which is half of the stated requirement.
- ✗
Encrypt the ISO with the vendor's public key and confirm the operation succeeds.
Why it's wrong here
Encrypting with the vendor's public key would produce ciphertext only the vendor's private key could decrypt, which is useful for confidentiality but irrelevant to verifying a downloaded file. It neither checks integrity nor confirms that the vendor produced the ISO. This action misunderstands the direction of asymmetric operations and does not address the administrator's verification goal.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.