Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium
A company is implementing a new policy requiring all sensitive data, both in transit and at rest, to be protected from unauthorized access. Which cybersecurity concept is primarily addressed by implementing encryption for this data?
- AAvailability
- BNon-repudiation
- CIntegrity
- DConfidentiality
Show answer & explanationAnswer & explanation
Correct answer: D. Confidentiality
Encryption is a primary control for ensuring confidentiality by rendering data unreadable to unauthorized parties, whether it's stored or being transmitted.
Why the other options are wrong
- A. Availability ensures resources are accessible to authorized users when needed.
- B. Non-repudiation provides proof of origin or delivery, preventing denial.
- C. Integrity ensures data has not been altered or tampered with.
Encryption and Confidentiality
Encryption is the process of converting information or data into a code, preventing unauthorized access. It is a fundamental tool for achieving confidentiality, ensuring only authorized parties can understand the data.
- Transforms plaintext into ciphertext.
- Requires a key to decrypt and access original data.
- Protects data both 'at rest' (stored) and 'in transit' (communicated).
Memory trick: Protecting data means keeping it Secret, Sound, and always On-call.