Cisco CCNP Security Core (SCOR) 350-701Security ConceptsEasy

A security analyst is investigating a recent breach where an unauthorized external party gained access to the company's internal network. The attacker exploited a known vulnerability in an unpatched web server and exfiltrated sensitive customer data. Which security principle was primarily compromised in this scenario?

  1. AAvailability
  2. BConfidentiality
  3. CIntegrity
  4. DNon-repudiation
Show answer & explanation

Correct answer: B. Confidentiality

The exfiltration of sensitive customer data directly compromises confidentiality, as unauthorized access to information occurred. The attacker gained access to information they were not authorized to see.

Why the other options are wrong

  • A. Availability refers to ensuring authorized users have access to resources when needed; this was not the primary compromise.
  • C. Integrity refers to maintaining the accuracy and completeness of data; while data might have been copied, it wasn't necessarily altered.
  • D. Non-repudiation ensures that a party cannot deny having performed an action; this is unrelated to the unauthorized access and data exfiltration.

Confidentiality

The security principle that ensures sensitive information is protected from unauthorized access, disclosure, or theft.

  • Prevents unauthorized viewing or access to data.
  • Often achieved through encryption, access controls, and proper data handling.
  • A cornerstone of the CIA triad.

Memory trick: Confidentiality means keeping secrets secret, like a locked diary.

More Security Concepts questions