How to ensure the authenticity of company-developed code?

A software development manager wants to ensure the authenticity of the code created by the company. Which of the following options is the most appropriate?

  1. Testing input validation on the user input fields
  2. Performing code signing on company-developed software Source Reference Answer
  3. Performing static code analysis on the software
  4. Ensuring secure cookies are use

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of cryptographic integrity controls for software distribution, where the common trap is confusing code signing with static code analysis or input validation, which address different security concerns.

Code signing uses digital signatures to verify the identity of the software developer and confirm that the code has not been altered since it was signed. The community unanimously agrees that code signing is the correct method to ensure code authenticity.

Option C (static code analysis) is a common wrong choice because candidates associate 'code' with security testing, but static analysis finds vulnerabilities rather than proving authenticity or origin.

Community Discussion (5 comments)

SHADTECH123 👍 9 Selected: B
Code signing involves applying a digital signature to software, verifying the identity of the developer and ensuring that the code has not been altered or tampered with since it was signed. This process provides assurance of the authenticity and integrity of the software. Testing input validation, performing static code analysis, and ensuring secure cookies are important security practices but do not specifically address the need to verify the authenticity of the code.
MaxiPrince 👍 1 Selected: B
Performing code signing on company-developed software
PAWarriors 👍 1 Selected: B
B. Code signing utilizes digital signatures to verify code authenticity and confirms the software author's identity and integrity
dbrowndiver 👍 1 Selected: B
Authenticity Verification: Code signing assures users and developers that the code is genuine and originates from a legitimate source. If the code is altered, the digital signature becomes invalid, alerting users to potential tampering.
Osechabelo 👍 1
B. Performing code signing on company-developed software

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Code signing applies a digital signature to software using a private key, allowing anyone with the corresponding public key to verify the developer's identity and confirm the code has not been tampered with. This directly addresses the manager's goal of ensuring authenticity. As comment [1] notes, code signing provides assurance of both authenticity and integrity of the software. Comment [3] reinforces that code signing confirms the software author's identity and integrity through digital signatures.

Why the Other Options Are Wrong

Option A (input validation) protects against injection attacks at runtime but does nothing to prove who wrote the code. Option C (static code analysis) scans source code for vulnerabilities and coding flaws but does not provide any cryptographic proof of origin or authenticity. Option D (secure cookies) is a web application security control related to session management and has no relevance to verifying code authorship or integrity.

Community Comment Notes

All five community comments unanimously support answer B, with comment [1] providing the most detailed explanation by distinguishing code signing from the other options. Comment [4] adds a useful point about how an invalid digital signature alerts users to potential tampering, highlighting the integrity-checking aspect of code signing. The strong consensus (100% votes for B) indicates this is a straightforward question for well-prepared candidates.

Official Reference

Exam Strategy

When a question asks about proving the origin or authenticity of software, immediately look for cryptographic solutions like digital signatures or code signing rather than testing or analysis methods. Remember that authenticity and integrity are solved by cryptography, while vulnerability detection is solved by testing and analysis tools.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide