Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesEasy
A small business owner is implementing basic cybersecurity measures. They are particularly concerned about unauthorized access to their customer database, which contains sensitive personal information. They want to ensure that only authenticated and authorized employees can view or modify this data. Which security principle is primarily addressed by implementing strong access controls and authentication mechanisms?
- AConfidentiality
- BIntegrity
- CNon-repudiation
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Confidentiality ensures that information is accessible only to those authorized to have access. Implementing strong access controls directly supports this principle by preventing unauthorized disclosure.
Why the other options are wrong
- B. Integrity ensures that data is accurate and not modified without authorization, which is a secondary concern.
- C. Non-repudiation provides proof of origin and delivery, preventing denial of actions, which is not the primary focus.
- D. Availability ensures that systems and data are accessible when needed, which is not the primary concern here.
Confidentiality
The security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes.
- Prevents unauthorized disclosure.
- Achieved through encryption, access controls, and authentication.
- Part of the CIA triad.
Memory trick: Confidentiality guards secrets, Integrity keeps truth, Availability ensures presence.