Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityEasy

A security auditor is reviewing a company's network and finds that sensitive data is being transmitted in cleartext over an internal network segment, making it vulnerable to eavesdropping. The auditor recommends implementing a cryptographic solution to protect this data in transit. Which cryptographic goal is primarily addressed by encrypting the data?

  1. AConfidentiality
  2. BIntegrity
  3. CAvailability
  4. DNon-repudiation
Show answer & explanation

Correct answer: A. Confidentiality

Encrypting data primarily addresses confidentiality, ensuring that only authorized individuals can read or access the information. This directly counters the vulnerability of eavesdropping on cleartext data.

Why the other options are wrong

  • B. Integrity ensures that data has not been altered or tampered with, which is different from preventing it from being read.
  • C. Availability ensures that systems and data are accessible when needed, not protected from eavesdropping.
  • D. Non-repudiation ensures that a party cannot deny having performed an action, which is not the primary goal of encryption against eavesdropping.

Confidentiality (CIA Triad)

Confidentiality, in the context of information security, refers to the protection of information from unauthorized access or disclosure.

  • Ensures data is kept secret
  • Protected by encryption, access controls
  • Prevents eavesdropping and unauthorized viewing

Memory trick: CIA: Confidentiality, Integrity, Availability – the pillars of security.

More Network Security questions