CISSP-ISSAP · Question #19
A digital signature is a type of public key cryptography. Which of the following statements are true about digital signatures? Each correct answer represents a complete solution. Choose all that…
The correct answer is C. In order to digitally sign an electronic record, a person must use his/her private key. D. In order to verify a digital signature, the signer's public key must be used. Digital signatures work on an asymmetric key pair where signing uses the private key (C) and verification uses the public key (D). A signer uses their private key - which only they possess - to encrypt a hash of the document, creating the signature; anyone can then use the…
Question
A digital signature is a type of public key cryptography. Which of the following statements are true about digital signatures? Each correct answer represents a complete solution. Choose all that apply.
Options
- AIn order to digitally sign an electronic record, a person must use his/her public key.
- BIn order to verify a digital signature, the signer's private key must be used.
- CIn order to digitally sign an electronic record, a person must use his/her private key.
- DIn order to verify a digital signature, the signer's public key must be used.
How the community answered
(22 responses)- A5% (1)
- B5% (1)
- C91% (20)
Explanation
Digital signatures work on an asymmetric key pair where signing uses the private key (C) and verification uses the public key (D). A signer uses their private key - which only they possess - to encrypt a hash of the document, creating the signature; anyone can then use the signer's freely available public key to decrypt and verify it. This design ensures both authenticity (only the private key holder could have signed it) and non-repudiation (the signer cannot deny it).
Why A and B are wrong: They swap the keys. Using a public key to sign (A) would mean anyone could forge your signature, since public keys are, by definition, public. Requiring the private key to verify (B) would be counterproductive - verifiers don't have (and shouldn't have) access to the signer's private key.
Memory tip: Think of it as a locked mailbox - your private key is the only key that locks (signs) outgoing mail, while your public key is the slot that anyone can use to open and read (verify) what you sent.
Topics
Community Discussion
No community discussion yet for this question.