CompTIA Tech+ (FC0-U71)SecurityMedium

A user is browsing a website and notices that the URL begins with 'HTTP' instead of 'HTTPS'. The website is asking for personal information, including credit card details. Which of the following security concerns is most relevant in this situation?

  1. ANon-repudiation
  2. BConfidentiality
  3. CAvailability
  4. DIntegrity
Show answer & explanation

Correct answer: B. Confidentiality

HTTP (Hypertext Transfer Protocol) does not encrypt data transmitted between the browser and the server, making it vulnerable to eavesdropping. When a website requests personal information over HTTP, the primary concern is the confidentiality of that data, as it could be intercepted by unauthorized parties.

Why the other options are wrong

  • A. Non-repudiation ensures actions cannot be denied, which is not the main concern with unencrypted data transmission.
  • C. Availability ensures access to data, which is not the primary issue with HTTP.
  • D. Integrity ensures data is not altered, but here the concern is disclosure.

Confidentiality (CIA Triad)

The principle that ensures information is protected from unauthorized access and disclosure, maintaining its privacy.

  • Prevents sensitive data from being seen by unauthorized users.
  • Achieved through encryption, access controls, and proper data handling.
  • Compromised by unencrypted transmission of sensitive data.

Memory trick: HTTP is not secure for C.I.A. (Confidentiality, Integrity, Availability).

More Security questions