Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesEasy

A newly hired cybersecurity analyst is reviewing a company's asset inventory. They identify several unpatched legacy servers running critical business applications that are directly accessible from the internet. Which foundational security concept is most directly violated by the presence of these unpatched, internet-facing systems?

  1. AAvailability
  2. BNon-repudiation
  3. CConfidentiality
  4. DIntegrity
Show answer & explanation

Correct answer: D. Integrity

Unpatched systems are vulnerable to exploits, which can lead to unauthorized modification or destruction of data, directly compromising its integrity. While confidentiality and availability could also be affected, the primary and most immediate risk from unpatched systems is data alteration or corruption.

Why the other options are wrong

  • A. Availability ensures that data and systems are accessible when needed, which can be affected but is not the primary concept violated by unpatched systems.
  • B. Non-repudiation ensures that a party cannot deny having performed an action, which is not the primary concern here.
  • C. Confidentiality protects data from unauthorized disclosure, which is a secondary risk but not the most direct violation.

Integrity (CIA Triad)

The assurance that information is accurate, consistent, and trustworthy throughout its entire lifecycle and has not been altered or destroyed in an unauthorized manner.

  • Protects against unauthorized modification or deletion.
  • Ensures data is reliable and uncorrupted.
  • Maintained through access controls, hashing, and backups.

Memory trick: CIA: Confidentiality, Integrity, Availability are the foundational pillars.

More Security Principles questions