Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A regulatory body requires that a company must implement measures to prevent the unauthorized disclosure of sensitive customer data. This includes encrypting data at rest and in transit, and restricting access to only those who explicitly need it for their job functions. Which core security principle is this requirement most aligned with?
- AAvailability
- BConfidentiality
- CNon-repudiation
- DIntegrity
Show answer & explanationAnswer & explanation
Correct answer: B. Confidentiality
Confidentiality aims to prevent the unauthorized disclosure of information. Encrypting data and restricting access are direct measures to uphold confidentiality.
Why the other options are wrong
- A. Availability ensures data and systems are accessible when needed, which is not the primary concern here.
- C. Non-repudiation ensures that an action cannot be denied by the perpetrator, which is related to accountability but not direct data disclosure prevention.
- D. Integrity focuses on preventing unauthorized modification of data, not disclosure.
Confidentiality
The security principle that ensures sensitive information is protected from unauthorized access, disclosure, or theft.
- Often achieved through encryption, access controls, and data masking.
- A cornerstone of the CIA triad.
- Crucial for protecting privacy and proprietary information.
Memory trick: Confidential means Covered and Coded