Cisco CCNP Security Core (SCOR) 350-701Security ConceptsEasy

During an incident response, a security analyst discovers that a threat actor has modified critical system files to maintain persistence and hide their activities. The analyst needs to restore the system to a known good state. Which core security principle has been directly compromised by the file modifications?

  1. AIntegrity
  2. BConfidentiality
  3. CAvailability
  4. DAccountability
Show answer & explanation

Correct answer: A. Integrity

Integrity ensures that data and systems remain accurate, complete, and untampered. The modification of critical system files by a threat actor directly violates this principle, as the system's state is no longer trustworthy or as intended.

Why the other options are wrong

  • B. Confidentiality protects data from unauthorized disclosure, not unauthorized modification.
  • C. Availability ensures systems and data are accessible, which might be affected indirectly but is not the primary principle violated by file modification.
  • D. Accountability links actions to individuals, which is related to forensics, but not the core principle compromised by data modification.

Integrity

The principle that data and systems are accurate, complete, and have not been modified by unauthorized entities or in an unauthorized manner.

  • Protects against unauthorized alteration or destruction.
  • Often maintained through hashing, digital signatures, and access controls.
  • Crucial for trustworthy data and system operations.

Memory trick: CIA: 'C' for 'Cover' the secrets, 'I' for 'Intact' data, 'A' for 'Always' there.

More Security Concepts questions