Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy
A hospital is implementing a new system to manage patient records. Due to the highly sensitive nature of the data, the system must ensure that only authorized medical staff can view patient information, and any attempt by unauthorized individuals to access this data is strictly prevented. Which security goal is paramount in this scenario?
- AAccountability
- BAvailability
- CIntegrity
- DConfidentiality
Show answer & explanationAnswer & explanation
Correct answer: D. Confidentiality
The requirement that 'only authorized medical staff can view patient information, and any attempt by unauthorized individuals to access this data is strictly prevented' directly addresses the principle of confidentiality, which is about preventing unauthorized disclosure of information.
Why the other options are wrong
- A. Accountability ensures that actions can be traced to an individual, but the primary goal here is preventing access itself.
- B. Availability focuses on ensuring systems and data are accessible when needed, not on preventing unauthorized viewing.
- C. Integrity focuses on preventing unauthorized modification of data, not unauthorized viewing.
Confidentiality
The principle of ensuring that information is accessed only by authorized individuals or systems, preventing unauthorized disclosure.
- Crucial for sensitive data like patient records, financial information, and intellectual property.
- Achieved through measures like encryption, access controls, and data classification.
- Part of the foundational CIA Triad of cybersecurity.
Memory trick: CIA: Keep it Secret, Safe, and Always Ready.