ISC2 CC Security Principles Practice Question
A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor signs the patch with its private key. Which security property does this provide to customers who verify the signature with the vendor's public key?
⚠ Common exam trap
The trap here is assuming that signing also encrypts the patch, but signatures provide integrity and origin proof, not confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Non-repudiation and integrity
A digital signature created with a private key and verified with the corresponding public key provides authenticity, integrity, and non-repudiation. Customers can confirm the patch came from the vendor and was not modified, and the vendor cannot later deny signing it. Confidentiality, availability, and authorization are separate properties not delivered by this signing and verification process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Non-repudiation and integrity
Why this is correct
Signing with a private key and verifying with the corresponding public key proves the patch originated from the vendor and was not altered. This provides non-repudiation because the vendor cannot deny signing it, and integrity because any modification invalidates the signature. Thus it correctly describes the security property.
- ✗
Confidentiality of the patch contents
Why it's wrong here
Digital signatures do not encrypt the patch; they provide authenticity and integrity. Anyone with the public key can verify the signature, but the patch contents remain readable unless separately encrypted. Therefore, confidentiality is not the property provided by signing and verifying the patch in this scenario.
- ✗
Authorization of the customer
Why it's wrong here
Authorization determines what an authenticated user is permitted to do. The signature verification process does not grant or check customer permissions; it validates the patch's origin and integrity. Therefore, authorization is not the property provided by the vendor's digital signature in this scenario.
- ✗
Availability of the download server
Why it's wrong here
Availability concerns reliable access to systems and data, often supported by redundancy and denial-of-service protection. A digital signature does not keep the download server online or ensure bandwidth. Since the scenario is about verifying origin and integrity, availability is not the property being provided.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Availability
Availability is the measure of how often a system or service is operational and accessible when needed, typically expressed as a percentage of uptime.
Key term
Non-repudiation
Non-repudiation is a security principle that ensures a party in a digital transaction cannot deny their involvement or the authenticity of their digital signature.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.