Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A software development team is building a new application that will store sensitive customer data. They need to implement a mechanism to prove the origin of the data and ensure that it has not been tampered with since its creation or last modification. Which security concept is most relevant here?

  1. ALeast Privilege
  2. BAvailability
  3. CNon-repudiation
  4. DConfidentiality
Show answer & explanation

Correct answer: C. Non-repudiation

Non-repudiation ensures that the origin of data can be verified and that the data has not been altered, preventing the sender from denying that they sent the message or the integrity of the data. This directly addresses the need to prove data origin and detect tampering.

Why the other options are wrong

  • A. Least Privilege limits user access to only what is necessary, not directly related to data origin or tampering proof.
  • B. Availability ensures that systems and data are accessible when needed.
  • D. Confidentiality focuses on preventing unauthorized disclosure of information.

Non-repudiation

The assurance that someone cannot deny the validity of something, typically a statement or action, by providing undeniable proof of origin and integrity.

  • Prevents denial of actions or data origin.
  • Often achieved using digital signatures and audit trails.
  • Crucial for legal and contractual agreements.

Memory trick: Non-repudiation is like a signed contract, proving who did what and that it hasn't been changed.

More Describe the concepts of security, compliance, and identity questions