DevNet Associate (DEVASC) v1.0Network FundamentalsMedium
A network developer is implementing a RESTful API for a network device. To ensure the API requests are secure and the data exchanged is confidential, which network security fundamental should be primarily addressed when designing the API communication?
- AConfidentiality
- BNon-repudiation
- CIntegrity
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Confidentiality ensures that information is accessible only to those authorized to have access. When the goal is to keep data 'secure' and 'confidential', this principle is paramount, typically achieved through encryption (e.g., HTTPS for RESTful APIs).
Why the other options are wrong
- B. Non-repudiation proves that a sender sent a message and a receiver received it, not directly related to keeping data secret.
- C. Integrity ensures that data has not been altered or tampered with, important but secondary to confidentiality for 'secure and confidential' data.
- D. Availability ensures resources are accessible when needed, relevant for API uptime but not directly for data secrecy.
CIA Triad
The CIA Triad (Confidentiality, Integrity, Availability) is a fundamental model for information security policies.
- Confidentiality: Protecting information from unauthorized access.
- Integrity: Ensuring information is accurate and has not been tampered with.
- Availability: Guaranteeing authorized users can access information when needed.
Memory trick: CIA: 'Confidentiality, Integrity, Availability' is the security core.