CompTIA Tech+ (FC0-U71)SecurityMedium
A security analyst is reviewing a company's incident response plan. The plan includes steps for identifying vulnerabilities, applying patches, and conducting regular security audits. Which of the following security principles is primarily being addressed by these actions?
- AIntegrity
- BNon-repudiation
- CAvailability
- DConfidentiality
Show answer & explanationAnswer & explanation
Correct answer: A. Integrity
Identifying vulnerabilities and applying patches directly relates to maintaining the integrity of data and systems by preventing unauthorized modification or corruption. Regular audits help ensure that integrity controls are effective.
Why the other options are wrong
- B. Non-repudiation ensures that an action or event cannot be denied by the party who performed it.
- C. Availability focuses on ensuring that systems and data are accessible to authorized users when needed.
- D. Confidentiality focuses on preventing unauthorized disclosure of information.
Integrity (CIA Triad)
The principle that ensures data and systems are accurate, complete, and protected from unauthorized modification or destruction.
- Prevents unauthorized changes to data.
- Ensures data consistency and trustworthiness.
- Achieved through hashing, access controls, backups, and patching.
Memory trick: CIA: Confidentiality is private, Integrity is true, Availability is always there.