Courseiva

Digital Signatures and Integrity

A healthcare organization uses digital signatures on electronic medical records to ensure that the records have not been tampered with during transmission. Which security goal is primarily being addressed by this practice?

Quick Answer

The answer is integrity. Digital signatures achieve this by hashing the electronic medical record and encrypting that hash with the sender’s private key; if the record is altered during transmission, the decrypted hash will not match a freshly computed hash, immediately flagging tampering. On the SC-900 exam, this scenario tests your ability to distinguish integrity from non-repudiation—a common trap where candidates confuse the goal of proving no tampering (integrity) with the goal of proving the signer’s identity (non-repudiation). Remember that while digital signatures can also provide non-repudiation, the question’s focus on “not been tampered with” directly points to integrity as the primary security goal. A helpful memory tip: integrity is about the data staying whole and unchanged, like a sealed envelope that shows signs of being opened, whereas non-repudiation is about proving who sealed it.

⚠ Common exam trap

It's easy for candidates to confuse integrity with non-repudiation, but the question's focus on 'tampered with during transmission' directly points to integrity, not the ability to prove who signed it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Integrity

Digital signatures use asymmetric cryptography (e.g., RSA or ECDSA) to create a hash of the electronic medical record, which is then encrypted with the signer's private key. Any tampering with the record during transmission will cause the hash verification to fail, directly ensuring data integrity. This practice does not primarily address confidentiality (which requires encryption) or availability (which focuses on uptime).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Confidentiality

    Why it's wrong here

    Confidentiality ensures data is only accessible to authorized parties, typically through encryption. Digital signatures focus on detecting tampering, not restricting access.

  • Integrity

    Why this is correct

    Integrity ensures data has not been altered by unauthorized parties. Digital signatures provide a mechanism to detect any changes, thus preserving integrity.

  • Availability

    Why it's wrong here

    Availability ensures systems and data are accessible when needed. Digital signatures do not directly address uptime or access reliability.

  • Non-repudiation

    Why it's wrong here

    Non-repudiation prevents a party from denying an action, like sending a message. While digital signatures support non-repudiation, the primary goal described is detecting tampering, which relates to integrity.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A financial institution uses digital signatures to ensure that a transaction record has not been altered after it was processed. Which security principle is primarily addressed?

easy
  • A.A. Confidentiality
  • B.B. Integrity
  • C.C. Availability
  • D.D. Non-repudiation

Why B: Digital signatures use asymmetric cryptography (e.g., RSA or ECDSA) to create a hash of the transaction record, which is then encrypted with the sender's private key. Any alteration to the record after signing would cause the hash verification to fail, directly ensuring data integrity. This is why option B is correct.

Variation 2. A financial institution uses digital signatures to sign all transaction records. This ensures that the records have not been altered after signing. Which security goal does this primarily protect?

easy
  • A.Confidentiality
  • B.Non-repudiation
  • C.Integrity
  • D.Availability

Why C: Digital signatures use asymmetric cryptography (e.g., RSA or ECDSA) to create a hash of the transaction record, which is then encrypted with the signer's private key. Any alteration to the record after signing would cause the hash verification to fail, directly protecting the integrity of the data. While digital signatures also support non-repudiation, the question specifically asks which goal is primarily protected by ensuring records have not been altered, which is integrity.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.