ISC2 CC Security Principles Practice Question
A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?
⚠ Common exam trap
The trap is confusing hashing with digital signatures — hashing detects alteration but does not prove who signed, so candidates who pick hashing miss the non-repudiation requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Digital signature
A digital signature uses asymmetric cryptography to sign a document's hash with the signer's private key, allowing anyone with the public key to verify both the signer's identity and that the document has not been altered. This provides integrity and non-repudiation, directly satisfying the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Symmetric encryption
Why it's wrong here
Symmetric encryption provides confidentiality, not tamper evidence; anyone holding the shared key can re-encrypt altered content undetectably. It is tempting because encryption protects the document in transit and at rest, making it the right choice when the requirement is keeping the signed contents secret rather than verifying integrity.
- ✓
Digital signature
Why this is correct
A digital signature uses asymmetric cryptography: the signer's private key creates a hash-based value that any verifier can check with the public key. Altering the document invalidates that value, directly satisfying the requirement to detect changes since signing.
- ✗
Access control list
Why it's wrong here
An access control list governs which identities may read or modify a resource; it cannot detect whether bytes changed after signing. It is tempting because ACLs protect documents from unauthorised edits, which would be the right control when the requirement is preventing alteration rather than proving none occurred.
- ✗
Hashing
Why it's wrong here
Hashing alone produces a digest but, without a digital signature or HMAC keyed to the signer, anyone can recompute it after altering the document. It is tempting because hashes underpin integrity checking, and would be correct when paired with asymmetric signing to bind the digest to the signer.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Non-repudiation
Non-repudiation is a security principle that ensures a party in a digital transaction cannot deny their involvement or the authenticity of their digital signature.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.