nerdexam
Isaca

CISM · Question #804

Which of the following should be an information security manager's MAIN concern if the same digital signing certificate is able to be used by two or more users?

The correct answer is D. Inability to validate identity of sender. A digital signing certificate is used to uniquely bind an individual’s identity to their cryptographic signature. If the same certificate can be used by multiple users, the information security manager’s primary concern is that the true sender of a digitally signed message…

Submitted by andres_qro· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following should be an information security manager's MAIN concern if the same digital signing certificate is able to be used by two or more users?

Options

  • ASeparation of duties
  • BCertificate alteration
  • CData encryption is weakened
  • DInability to validate identity of sender

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    15% (4)
  • C
    4% (1)
  • D
    73% (19)

Explanation

A digital signing certificate is used to uniquely bind an individual’s identity to their cryptographic signature. If the same certificate can be used by multiple users, the information security manager’s primary concern is that the true sender of a digitally signed message cannot be reliably identified, undermining nonrepudiation and trust in the signature.

Topics

#Digital Certificates#Digital Signatures#Non-repudiation#Identity Validation

Community Discussion

No community discussion yet for this question.

Full CISM Practice