CompTIA Tech+ (FC0-U71)SecurityHard

A user is attempting to access a website and notices that the URL begins with 'http://' instead of 'https://'. Additionally, the browser displays a warning about the connection not being secure. Which security concept is primarily lacking in this scenario?

  1. AAvailability
  2. BConfidentiality
  3. CNon-repudiation
  4. DIntegrity
Show answer & explanation

Correct answer: B. Confidentiality

The 'http://' protocol indicates an unencrypted connection, meaning any data transmitted between the user and the website can be intercepted and read by unauthorized parties, directly compromising confidentiality.

Why the other options are wrong

  • A. Availability ensures that the system and data are accessible; the website is accessible, but insecure.
  • C. Non-repudiation ensures a party cannot deny having performed an action; it's unrelated to the encryption status of a web connection.
  • D. Integrity ensures data has not been altered; while it could be altered, the immediate and primary concern with HTTP is the lack of encryption, which directly impacts confidentiality.

Confidentiality (CIA Triad)

The security principle that ensures that information is accessible only to those authorized to have access, protecting it from unauthorized disclosure.

  • Often achieved through encryption and access controls
  • One of the three pillars of the CIA Triad
  • Compromised by eavesdropping or unauthorized data viewing

Memory trick: CIA: Confidentiality, Integrity, Availability, keep data safe.

More Security questions