Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
A company is implementing a new security policy that requires all remote access to internal resources to be encrypted and authenticated using multi-factor authentication. Which security principle is primarily being addressed by these requirements?
- AConfidentiality
- BAvailability
- CIntegrity
- DNon-repudiation
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Encrypting data and requiring multi-factor authentication for remote access are primary controls for ensuring confidentiality, preventing unauthorized disclosure of information.
Why the other options are wrong
- B. Availability ensures systems and data are accessible when needed, not primarily addressed by encryption/MFA.
- C. Integrity ensures data is accurate and unaltered, not the main focus of encryption/MFA for access.
- D. Non-repudiation proves an action occurred, which is related to authentication but not its primary goal here.
Confidentiality
The security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes.
- Prevents unauthorized disclosure.
- Achieved through encryption, access control, authentication.
- Part of the 'CIA Triad' (Confidentiality, Integrity, Availability).
Memory trick: CIA: Confidentiality is keeping secrets, Integrity is keeping it true, Availability is keeping it there.