nerdexam
Oracle

1Z0-822 · Question #27

Consider the following: What is true concerning this publisher's Signature Policy?

The correct answer is D. Signed and unsigned packages from this publisher can be installed. Option D is correct because the publisher's Signature Policy shown is a permissive one (akin to IPS's verify policy) - it validates signatures when present but does not mandate that every package be signed, so both signed and unsigned packages from that publisher are…

Managing Software

Question

Consider the following:

What is true concerning this publisher's Signature Policy?

Exhibit

1Z0-822 question #27 exhibit

Options

  • AOnly packages from this publisher must have at least one valid signature.
  • BAll manifests from this publisher must have a cryptographic signature.
  • CAll newly installed packages must have at least one valid signature.
  • DSigned and unsigned packages from this publisher can be installed.

How the community answered

(40 responses)
  • B
    3% (1)
  • C
    5% (2)
  • D
    93% (37)

Explanation

Option D is correct because the publisher's Signature Policy shown is a permissive one (akin to IPS's verify policy) - it validates signatures when present but does not mandate that every package be signed, so both signed and unsigned packages from that publisher are installable.

Why the distractors are wrong:

  • A is wrong because it mischaracterizes the rule as targeting only this publisher's packages for a signature requirement, which isn't how policies work - they define behavior for all packages under that publisher, not a selective subset.
  • B is wrong because requiring all manifests to carry a cryptographic signature describes a stricter require-signatures policy, which is more restrictive than what's depicted.
  • C is wrong because mandating that all newly installed packages have at least one valid signature is again a stricter system-wide requirement, not a permissive publisher-level policy.

Memory tip: Anchor on the word "can" in option D - a permissive policy allows choice (signed OR unsigned), while wrong options use absolute language like "must" or "all," which signal a stricter require-signatures policy. If you see "must have a signature," that's the strict policy; if both are allowed, that's the permissive one.

Topics

#Package Signing#Publisher Policy#IPS#System Security

Community Discussion

No community discussion yet for this question.

Full 1Z0-822 Practice