SSCP Cryptography Practice Question
A security administrator needs to verify the integrity and authenticity of a downloaded software package. The vendor provides a separate file containing a cryptographic hash of the package, but the hash file itself is not signed. Which action BEST mitigates the risk of a modified package being accepted?
⚠ Common exam trap
The trap here is treating any hash comparison as sufficient for integrity, overlooking that the hash itself must come from a trusted source to provide assurance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain the hash value from a trusted, independent source and compare it to a locally computed hash.
Hashes alone provide integrity only when the reference value is trusted. Since the provided hash file is unsigned and could be altered alongside the package, the administrator must obtain the expected hash through an independent, authenticated channel. Comparing a locally computed hash against that trusted value detects tampering, whereas using the untrusted file or changing algorithms does not.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compare the provided hash with a hash computed locally using the same algorithm.
Why it's wrong here
Comparing hashes only confirms that the package matches the hash file. If an attacker modified both the package and the hash file in transit, the comparison would still succeed. This method does not establish authenticity because the hash file is not signed or obtained over a trusted channel, so it fails to mitigate the risk described.
- ✗
Decrypt the package using the vendor's public key before hashing it.
Why it's wrong here
The scenario does not indicate that the package is encrypted. Using the vendor's public key to decrypt assumes the vendor encrypted with its private key, which is not stated. Even if it were, decryption without verifying a signature does not prove integrity; an attacker could substitute a different encrypted package. This does not address the unsigned hash file problem.
- ✗
Recompute the hash using a different algorithm and compare it to the vendor's hash.
Why it's wrong here
Using a different algorithm produces a completely different digest, so a direct comparison is meaningless. The vendor's hash was generated with a specific algorithm, and changing it does not add trust. This approach would only create confusion and would not detect a modified package, because the reference hash remains untrusted.
- ✓
Obtain the hash value from a trusted, independent source and compare it to a locally computed hash.
Why this is correct
Integrity verification requires a trusted reference. By retrieving the hash from an independent, authenticated channel, the administrator can detect whether the package or the accompanying hash file was altered. A locally computed hash of the downloaded package compared against that trusted value provides assurance of integrity and authenticity, which the unsigned hash file alone cannot.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.