Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A company is implementing a new security strategy. They want to ensure that all data, whether in transit or at rest, is protected from unauthorized access. Which core security principle is primarily addressed by this objective?

  1. AIntegrity
  2. BConfidentiality
  3. CAvailability
  4. DNon-repudiation
Show answer & explanation

Correct answer: B. Confidentiality

Confidentiality is the principle that ensures data is kept private and accessible only to authorized individuals. Protecting data from unauthorized access directly aligns with this principle.

Why the other options are wrong

  • A. Integrity focuses on preventing unauthorized modification of data, not unauthorized access.
  • C. Availability focuses on ensuring data and systems are accessible when needed, not on preventing unauthorized access.
  • D. Non-repudiation ensures that an action cannot be denied by the originator, which is not the primary focus here.

Confidentiality

A core security principle ensuring that information is not disclosed to unauthorized individuals, entities, or processes.

  • Protects data privacy.
  • Prevents unauthorized access.
  • Often achieved through encryption and access controls.

Memory trick: Confidentiality Keeps Secrets Away from Curious Eyes.

More Describe the concepts of security, compliance, and identity questions