Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A software development team is building a new application that will store sensitive customer data. They want to ensure that even if a malicious actor gains access to the application's underlying database, they cannot deny having accessed or modified specific records. Which security concept is the team trying to implement?

  1. ANon-repudiation
  2. BConfidentiality
  3. CData Minimization
  4. DAvailability
Show answer & explanation

Correct answer: A. Non-repudiation

Non-repudiation ensures that a party cannot falsely deny having performed an action. This is typically achieved through digital signatures, logging, and auditing mechanisms that provide undeniable proof.

Why the other options are wrong

  • B. Confidentiality prevents unauthorized disclosure, but doesn't prevent denial of actions.
  • C. Data Minimization reduces the amount of data collected, which is a privacy principle, not directly addressing denial of actions.
  • D. Availability ensures access, which is unrelated to denying actions.

Non-repudiation

The assurance that someone cannot deny the validity of something. In security, it means a sender cannot deny sending a message, nor can a recipient deny receiving a message.

  • Provides undeniable proof of action or origin.
  • Often achieved using digital signatures and secure logging.
  • Crucial for legal and compliance requirements.

Memory trick: No Denying with Non-repudiation

More Describe the concepts of security, compliance, and identity questions