Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A security auditor is reviewing a web application and discovers that it is vulnerable to cross-site scripting (XSS) attacks. An attacker could inject malicious scripts into web pages viewed by other users. If successful, this could allow the attacker to steal session cookies, deface websites, or redirect users to malicious sites. Which component of the CIA triad is primarily compromised by a successful XSS attack that allows an attacker to steal user session cookies?
- AAvailability
- BNon-repudiation
- CConfidentiality
- DIntegrity
Show answer & explanationAnswer & explanation
Correct answer: C. Confidentiality
Confidentiality is compromised when an XSS attack successfully steals user session cookies. This allows an unauthorized attacker to gain access to sensitive information (the user's session) or impersonate the user, thereby breaching the privacy and secrecy of the user's interaction.
Why the other options are wrong
- A. Availability is about systems being accessible, which is not the primary impact of cookie theft.
- B. Non-repudiation ensures a party cannot deny an action, which is not directly impacted by cookie theft.
- D. Integrity is about data being accurate and untampered, which could be a secondary impact but not the primary one of cookie theft.
Confidentiality (CIA Triad)
The principle of the CIA triad that ensures that sensitive information is kept secret and is only accessible to authorized individuals or systems. It protects against unauthorized disclosure of information.
- Protects privacy and secrecy.
- Achieved through encryption, access control, data classification.
- Compromised by data breaches, unauthorized access, eavesdropping.
Memory trick: CIA: Confidentiality (secrets), Integrity (truth), Availability (always there).