Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsHard
A developer accidentally hardcodes sensitive credentials directly into the source code of a public-facing application. Which fundamental security concept is most directly violated by this action?
- AIntegrity
- BAvailability
- CConfidentiality
- DNon-repudiation
Show answer & explanationAnswer & explanation
Correct answer: C. Confidentiality
Hardcoding sensitive credentials into public-facing code directly exposes them to anyone who can view the code, violating the principle of Confidentiality by allowing unauthorized disclosure of information. If these credentials are then used, it can lead to further breaches.
Why the other options are wrong
- A. Integrity ensures data is accurate and not tampered with; while a breach might lead to integrity issues, the act of hardcoding credentials itself is a confidentiality flaw.
- B. Availability ensures systems and data are accessible when needed; hardcoding credentials doesn't directly impact this.
- D. Non-repudiation ensures that a party cannot deny having performed an action; this is unrelated to storing credentials insecurely.
Confidentiality
The security principle that ensures that information is not disclosed to unauthorized individuals, entities, or processes.
- Protects against unauthorized disclosure
- Achieved through encryption, access controls
- Part of the CIA triad
- Breaches often involve sensitive data exposure
Memory trick: CIA: 'C'onceal, 'I'ntegrate, 'A'ccess.