Which Characteristic Applies to Digital Signatures in Email?

Cryptography & Email Security
Answer Correct answer: C — A digital signature remains authentic and validates message integrity regardless of whether the email payload is encrypted.

Which of the following is a characteristic of a digital signature used for securing email transmissions?

  1. The signed message provides confidentiality and availability protection.
  2. The signature on one message can be transferred to another message.
  3. The signature is authentic whether or not it has been encrypted. Correct Answer
  4. The receiver only needs the public key to decrypt the message and verify the signature.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the independent function of digital signatures versus encryption, with the common trap confusing public key verification with message decryption.

Digital signatures ensure email authenticity and integrity using asymmetric cryptography. This page clarifies why option C is correct and debunks common misconceptions about key usage.

Option D is frequently chosen because learners mistakenly assume the sender’s public key decrypts the email, whereas it only verifies the signature.

Community Discussion (4 comments)

46080f2 👍 1 Selected: C
The CISA Review Manual (Source 1) clarifies that digital signatures validate authenticity and integrity without requiring message encryption. The Sybex Study Guide (Source 2) corroborates this, highlighting that digital signatures rely on hashing and asymmetric cryptography for verification, independent of message encryption.
Cisagroup 👍 1 Selected: C
A digital signature is based on public-key cryptography and remains authentic regardless of whether the message itself is encrypted. Encryption ensures confidentiality, but the digital signature only verifies the message's authenticity and integrity.
blehbleh 👍 1 Selected: C
Agreed with PurpleParrot
PurpleParrot 👍 3 Selected: C
option D is not correct as the public key is used to verify the signature, it is not used to decrypt the message. The sender typically encrypts the message with the recipient's public key, and the recipient uses their private key to decrypt it. i go with option C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Digital signatures rely on hashing and asymmetric cryptography to authenticate the sender and ensure data integrity. Option C correctly states that this verification process operates independently of message encryption. Whether the email body is encrypted or transmitted in plaintext, the cryptographic hash and the sender’s private key signature remain mathematically bound to the original content. This independence ensures that authenticity checks succeed even when confidentiality measures are disabled.

Why the Other Options Are Wrong

Option A incorrectly claims availability and confidentiality, which are handled by access controls and encryption protocols, not signatures. Option B violates cryptographic principles because signatures are uniquely generated from a message hash and cannot be copied or reused across different emails. Option D confuses key functions; the receiver uses their private key to decrypt the email, while the public key solely validates the signature.

Community Comment Notes

Learners consistently recognized that public keys verify signatures rather than decrypt payloads, aligning with PurpleParrot’s explanation that decryption requires the recipient’s private key. Multiple commenters echoed the CISA Review Manual’s stance that signatures validate authenticity and integrity without mandating encryption. As Cisagroup noted, the mechanism “remains authentic regardless of whether the message itself is encrypted.” This consensus reinforces the exam’s focus on separating cryptographic objectives.

Official Reference

Exam Strategy

Always separate cryptographic goals: signatures handle authentication, integrity, and non-repudiation, while encryption handles confidentiality. When reviewing CISA cryptography questions, map each mechanism to its exact purpose before evaluating options.

Frequently Asked Questions

Why can't the public key decrypt the email?

The sender encrypts the message with the recipient's public key, so only the recipient's private key can decrypt it. Public keys only verify signatures.

Do digital signatures provide confidentiality?

No, signatures only guarantee authenticity, integrity, and non-repudiation. Confidentiality requires separate symmetric or asymmetric encryption of the message body.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide