Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A small business is concerned about the impact of a potential ransomware attack. They want to implement a security measure that ensures even if their primary systems are infected and data is encrypted, they can restore their operations quickly without paying a ransom. Which core security principle is being directly addressed by this strategy?
- AAvailability
- BIntegrity
- CNon-repudiation
- DConfidentiality
Show answer & explanationAnswer & explanation
Correct answer: A. Availability
Availability ensures that authorized users can access systems and data when required. In a ransomware attack, the primary goal of the attacker is to deny availability. Implementing measures to restore operations quickly addresses the availability principle.
Why the other options are wrong
- B. Integrity protects against unauthorized modification, but restoring operations after encryption is mainly about availability.
- C. Non-repudiation ensures actions cannot be denied, which is not the focus of recovering from a ransomware attack.
- D. Confidentiality protects against unauthorized disclosure, which is a separate concern from operational recovery after a denial of service.
Availability
A core security principle ensuring that authorized users can reliably access information and resources when needed.
- Protects against denial of service (DoS) attacks.
- Ensures uptime and operational continuity.
- Often achieved through backups, redundancy, and disaster recovery plans.
Memory trick: Availability Always Allows Access.