Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A small business is concerned about the impact of a potential ransomware attack. They want to implement a security measure that ensures even if their primary systems are infected and data is encrypted, they can restore their operations quickly without paying a ransom. Which core security principle is being directly addressed by this strategy?

  1. AAvailability
  2. BIntegrity
  3. CNon-repudiation
  4. DConfidentiality
Show answer & explanation

Correct answer: A. Availability

Availability ensures that authorized users can access systems and data when required. In a ransomware attack, the primary goal of the attacker is to deny availability. Implementing measures to restore operations quickly addresses the availability principle.

Why the other options are wrong

  • B. Integrity protects against unauthorized modification, but restoring operations after encryption is mainly about availability.
  • C. Non-repudiation ensures actions cannot be denied, which is not the focus of recovering from a ransomware attack.
  • D. Confidentiality protects against unauthorized disclosure, which is a separate concern from operational recovery after a denial of service.

Availability

A core security principle ensuring that authorized users can reliably access information and resources when needed.

  • Protects against denial of service (DoS) attacks.
  • Ensures uptime and operational continuity.
  • Often achieved through backups, redundancy, and disaster recovery plans.

Memory trick: Availability Always Allows Access.

More Describe the concepts of security, compliance, and identity questions