Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

A vendor distributes a downloadable application and wants users to verify that the installer really came from the vendor and was not altered after release. Which control serves this purpose?

Code signing is the right control. The vendor applies a digital signature to the software, and users verify it with the publisher's certificate, confirming the installer's origin and that it has not been altered since signing. Masking, load balancing and normalisation do not provide this assurance.

  1. ACode signing using a digital signatureCorrect
  2. BData masking of the installer file
  3. CLoad balancing of the download server
  4. DDatabase normalisation

Explanation

Code signing applies the publisher's digital signature to software; the user's system verifies it using the publisher's certificate, confirming origin and that the code was not modified after signing. Data masking hides sensitive data, load balancing spreads traffic and normalisation organises database tables, so none assures authenticity and integrity.

Did you get it right without looking?

One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.

More Softwares and Software Security questions