Courseiva
Cryptography →hardMultiple Choice

SSCP Cryptography Practice Question

A security engineer is implementing a digital signature scheme to ensure non-repudiation. Which process correctly describes how a digital signature is created and verified?

⚠ Common exam trap

ISC2 often tests the misconception that the public key is used for signing because it is 'publicly available,' but the trap is that signing requires the private key to ensure only the claimed signer could have produced the signature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign with private key, verify with public key

A digital signature is created by hashing the message and then encrypting that hash with the signer's private key. Verification is performed by decrypting the signature with the signer's public key and comparing the result to a freshly computed hash of the message. This asymmetric process ensures non-repudiation because only the private key holder could have created the signature, while anyone with the public key can verify it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sign with private key, verify with public key

    Why this is correct

    The signer hashes the message and encrypts that digest with their private key; the verifier decrypts it with the signer's public key and compares digests. Only the private-key holder could produce it, so this binds identity and delivers non-repudiation.

  • ✗

    Sign with public key, verify with private key

    Why it's wrong here

    Digital signatures invert this: the private key signs and the public key verifies, so this ordering cannot provide non-repudiation. It is tempting because public-key encryption does use the public key to encrypt and the private key to decrypt, which is the opposite operation from signing.

  • ✗

    Sign with symmetric key, verify with asymmetric key

    Why it's wrong here

    Symmetric keys are shared, so any holder could produce the signature, defeating non-repudiation; signatures use asymmetric key pairs. It is tempting because symmetric cryptography is fast and does provide integrity via MACs, which would suit shared-secret message authentication between two trusted parties.

  • ✗

    Sign with hash, verify with private key

    Why it's wrong here

    A hash is not a key; signing requires encrypting the hash with the signer's private key, and verification uses the public key. It is tempting because hashing is genuinely part of signing, providing the fixed-length digest, but a bare hash alone cannot bind identity or prove origin.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?

medium
  • A.Recipient's public key to sign, recipient's private key to verify
  • ✓ B.Sender's private key to sign, sender's public key to verify
  • C.Sender's public key to sign, recipient's private key to verify
  • D.A shared symmetric key for both signing and verification

Why B: Digital signatures use asymmetric cryptography where the sender creates a signature with their private key, and the recipient verifies it with the sender's public key. This ensures non-repudiation because only the sender possesses their private key, so they cannot deny having signed the document. The process typically involves hashing the document and encrypting the hash with the sender's private key.

Variation 2. An organization is implementing a digital signature solution to ensure non-repudiation and integrity of documents. Which three of the following are true regarding digital signatures?

medium
  • A.The receiver uses the sender's private key to verify the signature.
  • ✓ B.The receiver verifies the signature using the sender's public key.
  • C.The sender encrypts the entire document with their public key to create a signature.
  • ✓ D.Digital signatures provide non-repudiation because the private key is kept secret by the sender.
  • ✓ E.The sender signs the message hash with their private key.

Why B: Option B is correct because signature verification always uses the sender's public key: the receiver decrypts the signature value with that public key and compares the recovered hash to a freshly computed hash of the message. Option D is correct because non-repudiation rests on the sender being the sole holder of the private key, so a signature that validates under the sender's public key could only have been produced by that sender, binding them to the document. Option E is correct because signing operates on a message digest, not the whole document: the sender hashes the message and then encrypts (signs) that hash with their private key, which is efficient and preserves integrity. Option A is wrong because the private key is never shared with the receiver; verification uses the public key. Option C is wrong because encrypting the entire document with the sender's public key would not create a signature and would be nonsensical, since the sender's public key is not used for signing and the sender does not hold the matching private key for decryption by others.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.