A company wants what PGP gives it — encrypted bodies, a signature identifying the author, tamper detection — but insists on an IETF standard layered onto the MIME format its clients already parse. Which does it deploy?
A company wants what PGP gives it — encrypted bodies, a signature identifying the author, tamper detection — but insists on an IETF standard layered onto the MIME format its clients already parse. Which does it deploy?
Answer
S/MIME
Options - A. S/MIME - B. DKIM - C. MIME - D. HTTPS Why - A. Correct. S/MIME layers signing and enveloping onto MIME and is defined principally by RFC 8551. - B. DKIM signs at the domain level and offers no confidentiality at all, so it is not the same functionality. - C. The trap for anyone reading only the first four letters. MIME is the parent format S/MIME extends, and it has no security features whatsoever. - D. HTTPS secures a web transport connection, not a stored-and-forwarded mail message.
Stallings & Brown 5e ch22 §22.1–22.2; RFC 8551; RFC 6376