- Home
- All questions
- Question 226
CompTIA Security+ study material · question 226 of 611
A signed vendor update is later found to contain malicious code. What does this show about signature verification?
Show the answer
Answer: B. Verification proves origin, so build pipeline integrity is a separate requirement
If the pipeline is compromised, the malicious artefact is genuinely signed and every downstream check passes.
Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Software and Data Integrity Failures