Courseiva
Cryptography →mediumMultiple Choice

SSCP Cryptography Practice Question

A security engineer is designing a system that requires non-repudiation of data origin. Which cryptographic technique should be used?

⚠ Common exam trap

Many exam-takers confuse integrity (provided by HMAC or hash) with non-repudiation, or assume a shared secret (HMAC or symmetric encryption) can prove origin, but only asymmetric digital signatures satisfy the legal requirement of non-repudiation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Digital signature using RSA or ECDSA

Digital signatures using RSA or ECDSA provide non-repudiation of data origin because they bind the signer's identity to the data through a private key that only the signer possesses. The recipient can verify the signature with the corresponding public key, and the signer cannot later deny having signed the data, as the private key is uniquely under their control. This meets the legal and technical requirement for non-repudiation, unlike symmetric or hash-only methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Keyed hash (HMAC)

    Why it's wrong here

    An HMAC uses a symmetric shared key, so either party could compute the tag, providing integrity and authenticity but no proof of origin to a third party. It is tempting because HMACs do verify message integrity, yet non-repudiation requires an asymmetric private key held by one signer only.

  • ✓

    Digital signature using RSA or ECDSA

    Why this is correct

    A digital signature binds the signer's private key to the message, letting any verifier confirm origin and integrity with the public key while the signer cannot later deny signing. RSA and ECDSA both provide this non-repudiation property.

  • ✗

    Hash function only

    Why it's wrong here

    A bare hash function provides integrity checking only; anyone can recompute the digest, so it cannot bind data to an originator. It is tempting because hashing detects tampering, but non-repudiation requires the hash to be signed with a private key unique to the sender.

  • ✗

    Symmetric encryption with a shared key

    Why it's wrong here

    Symmetric encryption with a shared key proves nothing about origin, since both parties hold the same key and either could have produced the ciphertext. It is tempting because it does provide confidentiality, but non-repudiation demands a private key known to a single signer, as in digital signatures.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.