Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A financial institution is implementing stringent security controls to protect customer transaction data. They require that data be encrypted both when stored on servers (at rest) and when being transmitted between systems (in transit). Which security principle is being directly addressed by this dual encryption requirement?
- AConfidentiality
- BNon-repudiation
- CIntegrity
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Confidentiality ensures that sensitive information is accessible only to authorized individuals. Encrypting data both at rest and in transit directly protects against unauthorized disclosure, thereby upholding the principle of confidentiality.
Why the other options are wrong
- B. Non-repudiation provides proof of the origin of data or a transaction, preventing denial of involvement, typically achieved with digital signatures, not encryption for data protection.
- C. Integrity ensures that data has not been altered or tampered with, which is often protected by hashing or digital signatures, not primarily by encryption for confidentiality.
- D. Availability ensures that systems and data are accessible when needed, which encryption can sometimes hinder if not managed correctly, but it's not its primary goal.
CIA Triad
A fundamental model for cybersecurity, representing the three core security goals: Confidentiality, Integrity, and Availability.
- Confidentiality: Protecting data from unauthorized access.
- Integrity: Ensuring data accuracy and preventing unauthorized modification.
- Availability: Guaranteeing access to legitimate users when needed.
Memory trick: CIA: Confidentiality is secrets, Integrity is truth, Availability is always there.