A company wants to verify that the software the company is deploying came from the vendor the company purchased the software from. Which of the following is the best way for the company to confirm this information?
Choose an answer
Tap an option to check your answer.
Correct answer: Validate the code signature..
Why this is the answer
Validating the code signature is the best way to verify the software's origin and integrity. Code signing uses digital certificates to cryptographically bind a software publisher's identity to the code, ensuring it hasn't been tampered with since it was signed by the legitimate vendor. Executing the code in a sandbox is a good security practice for analyzing unknown or suspicious software, but it doesn't confirm the vendor's identity or the software's authenticity. Searching for ASCII strings might reveal some information about the software but does not verify its origin. Generating a hash of the files can confirm file integrity against a known good hash, but without a trusted source for the original hash, it doesn't confirm the vendor's identity.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed