A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?
A digital signature uses asymmetric cryptography: the signer's private key creates a hash-based value that any verifier can check with the public key. Altering the document invalidates that value, directly satisfying the requirement to detect changes since signing.
Why this answer
A digital signature uses asymmetric cryptography to sign a document's hash with the signer's private key, allowing anyone with the public key to verify both the signer's identity and that the document has not been altered. This provides integrity and non-repudiation, directly satisfying the requirement.
Exam trap
The trap is confusing hashing with digital signatures — hashing detects alteration but does not prove who signed, so candidates who pick hashing miss the non-repudiation requirement.
How to eliminate wrong answers
Option A is wrong because symmetric encryption provides confidentiality, not integrity verification or proof of origin. Option C is wrong because an ACL controls access permissions to resources, not document integrity. Option D is wrong because hashing alone detects alteration but does not bind the hash to a signer, so it cannot prove who signed or prevent an attacker from replacing both the document and its hash.