How to ensure the authenticity of company-developed code?
A software development manager wants to ensure the authenticity of the code created by the company. Which of the following options is the most appropriate?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests knowledge of cryptographic integrity controls for software distribution, where the common trap is confusing code signing with static code analysis or input validation, which address different security concerns.
Code signing uses digital signatures to verify the identity of the software developer and confirm that the code has not been altered since it was signed. The community unanimously agrees that code signing is the correct method to ensure code authenticity.
Option C (static code analysis) is a common wrong choice because candidates associate 'code' with security testing, but static analysis finds vulnerabilities rather than proving authenticity or origin.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Code signing applies a digital signature to software using a private key, allowing anyone with the corresponding public key to verify the developer's identity and confirm the code has not been tampered with. This directly addresses the manager's goal of ensuring authenticity. As comment [1] notes, code signing provides assurance of both authenticity and integrity of the software. Comment [3] reinforces that code signing confirms the software author's identity and integrity through digital signatures.Why the Other Options Are Wrong
Option A (input validation) protects against injection attacks at runtime but does nothing to prove who wrote the code. Option C (static code analysis) scans source code for vulnerabilities and coding flaws but does not provide any cryptographic proof of origin or authenticity. Option D (secure cookies) is a web application security control related to session management and has no relevance to verifying code authorship or integrity.Community Comment Notes
All five community comments unanimously support answer B, with comment [1] providing the most detailed explanation by distinguishing code signing from the other options. Comment [4] adds a useful point about how an invalid digital signature alerts users to potential tampering, highlighting the integrity-checking aspect of code signing. The strong consensus (100% votes for B) indicates this is a straightforward question for well-prepared candidates.Official Reference
Exam Strategy
When a question asks about proving the origin or authenticity of software, immediately look for cryptographic solutions like digital signatures or code signing rather than testing or analysis methods. Remember that authenticity and integrity are solved by cryptography, while vulnerability detection is solved by testing and analysis tools.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →