CompTIA Tech+ (FC0-U71)SecurityMedium

A user is attempting to browse a website and notices that the URL begins with 'http://' instead of 'https://'. The user is concerned about the security of any information they might submit to the site. Which aspect of the CIA Triad is primarily at risk in this scenario?

  1. AConfidentiality
  2. BAvailability
  3. CIntegrity
  4. DAccountability
Show answer & explanation

Correct answer: A. Confidentiality

HTTP (Hypertext Transfer Protocol) transmits data in plain text, making it vulnerable to eavesdropping. HTTPS (HTTP Secure) uses encryption to protect data in transit. Therefore, without HTTPS, the confidentiality of any information submitted (like login credentials or personal data) is at risk because it could be intercepted and read by unauthorized parties.

Why the other options are wrong

  • B. Availability refers to ensuring access to data and systems. The 'http://' protocol itself doesn't directly impact availability.
  • C. Integrity refers to preventing unauthorized modification of data. While HTTP doesn't prevent modification, the primary concern with 'http://' is the lack of encryption for snooping.
  • D. Accountability refers to tracing actions to an individual. While related to security, it's not the primary concern highlighted by the lack of HTTPS encryption for data in transit.

Confidentiality (CIA Triad)

The principle of preventing unauthorized disclosure of information, ensuring that data is accessible only to those authorized to see it.

  • Often achieved through encryption and access controls.
  • Protects against eavesdropping and data breaches.
  • One of the three core principles of information security (Confidentiality, Integrity, Availability).

Memory trick: Confidentiality for secrets, Integrity for truth, Availability for access.

More Security questions