CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityEasy

A cloud architect is designing a new cloud environment for a financial institution that will process highly sensitive customer data. The institution is subject to stringent regulatory requirements regarding data integrity and non-alteration. Which security principle should be a primary consideration to ensure that data, once recorded, cannot be changed or deleted without detection?

  1. AConfidentiality
  2. BNon-repudiation
  3. CIntegrity
  4. DAvailability
Show answer & explanation

Correct answer: C. Integrity

Data integrity ensures that data remains accurate, consistent, and unaltered over its entire lifecycle. For sensitive financial data subject to regulatory scrutiny, ensuring that data cannot be changed or deleted without detection is paramount to maintaining its trustworthiness and compliance.

Why the other options are wrong

  • A. Confidentiality protects data from unauthorized access, but not from unauthorized alteration.
  • B. Non-repudiation prevents denial of actions, but integrity specifically addresses the prevention of undetected alteration.
  • D. Availability ensures that authorized users can access data when needed, which is different from preventing alteration.

Data Integrity

The assurance that data is accurate, consistent, and complete throughout its entire lifecycle and has not been altered or destroyed in an unauthorized manner.

  • Protects against unauthorized modification or deletion.
  • Essential for trust, compliance, and accuracy.
  • Often implemented through hashing, digital signatures, and access controls.

Memory trick: CIA: Confidentiality is secrecy, Integrity is truth, Availability is always there.

More Governance, Risk, Compliance and Security questions