Study. uk . com
  1. Home
  2. All questions
  3. Question 226

CompTIA Security+ study material · question 226 of 611

A signed vendor update is later found to contain malicious code. What does this show about signature verification?

  1. The signature must have been forged
  2. Verification proves origin, so build pipeline integrity is a separate requirement
  3. The certificate authority is liable for the content
  4. Signature checking should be disabled for vendor updates
Show the answer

Answer: B. Verification proves origin, so build pipeline integrity is a separate requirement

If the pipeline is compromised, the malicious artefact is genuinely signed and every downstream check passes.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Software and Data Integrity Failures

Challenge yourself on this topic → Study as cards