Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A software development team is building a new application that will store sensitive customer data. They want to ensure that even if a malicious actor gains access to the application's underlying database, they cannot deny having accessed or modified specific records. Which security concept is the team trying to implement?
- ANon-repudiation
- BConfidentiality
- CData Minimization
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Non-repudiation
Non-repudiation ensures that a party cannot falsely deny having performed an action. This is typically achieved through digital signatures, logging, and auditing mechanisms that provide undeniable proof.
Why the other options are wrong
- B. Confidentiality prevents unauthorized disclosure, but doesn't prevent denial of actions.
- C. Data Minimization reduces the amount of data collected, which is a privacy principle, not directly addressing denial of actions.
- D. Availability ensures access, which is unrelated to denying actions.
Non-repudiation
The assurance that someone cannot deny the validity of something. In security, it means a sender cannot deny sending a message, nor can a recipient deny receiving a message.
- Provides undeniable proof of action or origin.
- Often achieved using digital signatures and secure logging.
- Crucial for legal and compliance requirements.
Memory trick: No Denying with Non-repudiation