nerdexam
CompTIA

CAS-001 · Question #352

The marketing department at Company A regularly sends out emails signed by the company's Chief Executive Officer (CEO) with announcements about the company. The CEO sends company and personal emails…

The correct answer is B. Non-repudiation. Non-repudiation is the property that ensures a party cannot deny having performed an action. Because the corporate PKI issues one certificate per user and the CEO did not share their password, any email digitally signed with the CEO's private key can only have originated from…

Enterprise Security

Question

The marketing department at Company A regularly sends out emails signed by the company's Chief Executive Officer (CEO) with announcements about the company. The CEO sends company and personal emails from a different email account. During legal proceedings against the company, the Chief Information Officer (CIO) must prove which emails came from the CEO and which came from the marketing department. The email server allows emails to be digitally signed and the corporate PKI provisioning allows for one certificate per user. The CEO did not share their password with anyone. Which of the following will allow the CIO to state which emails the CEO sent and which the marketing department sent?

Options

  • AIdentity proofing
  • BNon-repudiation
  • CKey escrow
  • DDigital rights management

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    88% (30)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Non-repudiation is the property that ensures a party cannot deny having performed an action. Because the corporate PKI issues one certificate per user and the CEO did not share their password, any email digitally signed with the CEO's private key can only have originated from the CEO's account. The CIO can present the digital signatures on those emails as cryptographic proof of authorship. Identity proofing (A) is the process of verifying identity before issuing credentials, not proving past actions. Key escrow (C) involves storing copies of encryption keys, not proving message origin. Digital rights management (D) controls how content is used or distributed, not who sent a message.

Topics

#digital signatures#non-repudiation#PKI#email security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice