Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy
A large multinational corporation is developing a new security policy for its cloud infrastructure. The policy mandates that all data stored in the cloud must be encrypted both in transit and at rest, regardless of its classification. This policy aims to protect data even if the cloud provider's physical security is compromised. Which security goal is this policy primarily trying to achieve?
- AAvailability
- BConfidentiality
- CIntegrity
- DUtility
Show answer & explanationAnswer & explanation
Correct answer: B. Confidentiality
Encrypting data in transit and at rest primarily protects its confidentiality by ensuring that unauthorized individuals cannot read or understand the data, even if they gain access to it.
Why the other options are wrong
- A. Availability ensures that authorized users can access data when needed.
- C. Integrity ensures that data has not been altered or destroyed in an unauthorized manner.
- D. Utility refers to the usefulness of the information.
Confidentiality
The security principle that ensures sensitive information is protected from unauthorized disclosure or access.
- Often achieved through encryption, access controls, and data classification.
- Aims to prevent data from falling into the wrong hands.
- One of the core tenets of the CIA triad.
Memory trick: Confidentiality, Integrity, Availability - the core of information security.