nerdexam
(ISC)2

CSSLP · Question #75

Which of the following is an example of over-the-air (OTA) provisioning in digital rights management?

The correct answer is A. Use of shared secrets to initiate or rebuild trust. Over-the-air (OTA) provisioning in digital rights management (DRM) often involves the secure exchange of shared secrets to establish or rebuild trust with a device.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following is an example of over-the-air (OTA) provisioning in digital rights management?

Options

  • AUse of shared secrets to initiate or rebuild trust.
  • BUse of software to meet the deployment goals.
  • CUse of concealment to avoid tampering attacks.
  • DUse of device properties for unique identification.

How the community answered

(48 responses)
  • A
    90% (43)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Why each option

Over-the-air (OTA) provisioning in digital rights management (DRM) often involves the secure exchange of shared secrets to establish or rebuild trust with a device.

AUse of shared secrets to initiate or rebuild trust.Correct

Over-the-air (OTA) provisioning, especially in the context of digital rights management (DRM), frequently involves securely transmitting cryptographic keys or shared secrets to a device to establish or rebuild a trust relationship. This secure key exchange allows for the reliable delivery and management of digital content and associated rights, ensuring only authorized devices can access it.

BUse of software to meet the deployment goals.

Using software to meet deployment goals is a broad statement and not specific to the secure trust provisioning aspect of OTA in DRM. It describes a general objective rather than a mechanism for establishing trust.

CUse of concealment to avoid tampering attacks.

Use of concealment to avoid tampering attacks is a security tactic (security through obscurity) but is not a direct method of OTA provisioning for trust establishment. It does not explain how a device gains initial trust or is re-provisioned.

DUse of device properties for unique identification.

Using device properties for unique identification is a method for distinguishing devices, not the process of securely provisioning or re-establishing trust over-the-air. Identification precedes or complements provisioning, but is not the provisioning itself.

Concept tested: DRM OTA Provisioning, Trust establishment

Topics

#OTA Provisioning#Digital Rights Management#Shared Secrets#Cryptographic Trust

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice