DevNet Associate (DEVASC) v1.0Network FundamentalsMedium
A network developer is implementing a secure API for a network device. The API needs to ensure that only authorized users can access specific functions, and that the data exchanged with the device cannot be tampered with during transit. Which two security principles are primarily addressed by these requirements?
- AConfidentiality and Availability
- BAuthorization and Confidentiality
- CAuthentication and Integrity
- DIntegrity and Non-repudiation
Show answer & explanationAnswer & explanation
Correct answer: C. Authentication and Integrity
The requirement 'only authorized users can access specific functions' directly addresses Authentication (verifying identity) and Authorization (granting specific permissions). The requirement 'data exchanged... cannot be tampered with' directly addresses Integrity (ensuring data has not been altered).
Why the other options are wrong
- A. Confidentiality protects data from unauthorized disclosure, but 'access specific functions' is about who can do what. Availability ensures access to resources, not who can access functions or data tampering.
- B. Authorization grants permissions. Confidentiality protects data from unauthorized disclosure, but the question emphasizes 'access specific functions' (Auth/Auth) and 'cannot be tampered with' (Integrity).
- D. Integrity addresses data tampering. Non-repudiation ensures someone cannot deny an action, which isn't explicitly stated here as the primary concern.
CIA Triad and Related Principles
Fundamental security principles including Confidentiality, Integrity, and Availability, often extended with Authentication, Authorization, and Non-repudiation.
- Authentication: Verifies identity.
- Authorization: Grants permissions to access resources or functions.
- Integrity: Ensures data is accurate and has not been altered.
Memory trick: CIA+AAN: Always Authenticate, Authorize, and Never Tamper.