220-1102 exam dumps

220-1102 practice question 556 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 556

Single answerHashing

A technician downloads a security patch for several Windows PCs from the software vendor's website. The vendor also publishes a SHA-256 hash value for the file. Before deploying the patch, the technician wants to verify that the download was not altered or corrupted. Which action should the technician take?

  1. A

    Calculate the SHA-256 hash of the downloaded file and compare it to the vendor's published SHA-256 value

  2. B

    Open the file properties and confirm the file size matches what is shown on the website

  3. C

    Run the patch on a test PC first; if it installs, the file integrity is confirmed

  4. D

    Encrypt the patch file with BitLocker before copying it to other PCs

Show answer and explanation

Correct answer: A

Explanation

The best practice is to use the same hashing algorithm published by the vendor and compare the computed value of the downloaded file against the official hash. In this scenario, because the vendor provided a SHA-256 hash, the technician should calculate the SHA-256 hash locally and compare the two values. This validates file integrity and helps detect corruption or tampering. File size checks and test installations are not cryptographic integrity controls. Encryption tools such as BitLocker protect data at rest but do not verify download authenticity. This aligns with standard security best practices and common vendor guidance for software distribution, where checksums or hashes such as SHA-256 are provided so administrators can validate downloads before deployment.

  • A. Correct.

    Correct. Hashing is commonly used to verify file integrity. If the technician computes the SHA-256 hash of the downloaded patch and it matches the vendor's published SHA-256 value, that strongly indicates the file has not been modified or corrupted since the vendor created that hash.

  • B. Incorrect.

    Incorrect. Matching file size is not a reliable integrity check. Different files can have the same size, and a maliciously altered or corrupted file might still match the expected size. This is a common misconception because file size is easy to check, but it does not provide cryptographic validation.

  • C. Incorrect.

    Incorrect. A successful installation does not prove the file is authentic or unchanged. Malware can still execute, and some tampered files may partially or fully install. Testing functionality is not the same as verifying integrity with a hash.

  • D. Incorrect.

    Incorrect. BitLocker is used to encrypt storage volumes, not to verify whether a downloaded file matches the vendor's original file. Encrypting the patch after download does nothing to confirm that the file was safe or intact when obtained.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam