CompTIA Security+ (SY0-701)General Security ConceptsEasy
A hospital encrypts all patient records stored on its database servers so that even if an attacker steals the physical hard drives, the data cannot be read without the decryption key. Which principle of the CIA triad is primarily being protected by this control?
- ANon-repudiation
- BAvailability
- CConfidentiality
- DAccounting
Show answer & explanationAnswer & explanation
Correct answer: C. Confidentiality
Encrypting data at rest ensures that only authorized parties with the decryption key can read the information, which is the definition of confidentiality. Availability concerns uptime, non-repudiation is not part of the CIA triad, and accounting is a separate AAA function.
Why the other options are wrong
- A. Non-repudiation is about proving actions occurred, unrelated to encryption of stored data.
- B. Availability relates to systems being accessible, not to preventing unauthorized reading.
- D. Accounting tracks user activity, not data secrecy.
Confidentiality
One of the three pillars of the CIA triad; ensures that information is disclosed only to authorized individuals or systems.
- Achieved through encryption, access controls, and classification.
- Breaches of confidentiality result in unauthorized data disclosure.
- Encryption at rest and in transit are common confidentiality controls.
Memory trick: Confidentiality = keep it Closed to outsiders