nerdexam
CompTIA

CAS-005 · Question #303

A security team determines that the most significant risks within the pipeline are: - Unauthorized code changes - The current inability to perform independent verification of software modules Which…

The correct answer is A. Code signing. A security team seeks to address risks within their pipeline related to unauthorized code changes and the inability to independently verify software modules.

Submitted by kwame.gh· Mar 6, 2026Security Engineering

Question

A security team determines that the most significant risks within the pipeline are:

  • Unauthorized code changes
  • The current inability to perform independent verification of software

modules Which of the following best addresses these concerns?

Options

  • ACode signing
  • BDigital signatures
  • CNon-repudiation
  • DLightweight cryptography

How the community answered

(26 responses)
  • A
    92% (24)
  • B
    4% (1)
  • C
    4% (1)

Why each option

A security team seeks to address risks within their pipeline related to unauthorized code changes and the inability to independently verify software modules.

ACode signingCorrect

Code signing uses digital signatures to verify the authenticity and integrity of software, ensuring that the code has not been tampered with since it was signed and identifying the publisher. This directly addresses unauthorized code changes and enables independent verification of software modules.

BDigital signatures

Digital signatures are the underlying technology for code signing, but 'code signing' is the more specific and complete solution for verifying the integrity and authenticity of software modules.

CNon-repudiation

Non-repudiation is the assurance that an action cannot be denied, a property enabled by digital signatures, but it is not a direct mechanism for preventing unauthorized code changes or verifying software modules on its own.

DLightweight cryptography

Lightweight cryptography refers to encryption algorithms designed for resource-constrained environments and does not directly address unauthorized code changes or software module verification.

Concept tested: Code integrity and authenticity

Source: https://learn.microsoft.com/en-us/windows-hardware/drivers/install/driver-signing

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice