EC-Council Certified Ethical Hacker (CEH) v12CryptographyEasy

A security analyst is investigating a suspected man-in-the-middle (MITM) attack where an attacker intercepted and modified encrypted communications between two parties. The analyst found that while the data integrity was compromised, the confidentiality of the original messages was largely maintained due to strong symmetric encryption keys. Which cryptographic goal was primarily violated in this scenario?

  1. AAvailability
  2. BConfidentiality
  3. CIntegrity
  4. DNon-repudiation
Show answer & explanation

Correct answer: C. Integrity

The scenario explicitly states that the attacker 'modified encrypted communications' and that 'data integrity was compromised.' While confidentiality was largely maintained, the ability to ensure the data had not been altered was lost, which is the definition of integrity.

Why the other options are wrong

  • A. Availability refers to the ability to access information when needed, which is not described as being compromised.
  • B. Confidentiality was largely maintained, as stated in the scenario.
  • D. Non-repudiation ensures that a party cannot deny having performed an action, which is not the primary issue here.

Data Integrity

Data integrity ensures that information has not been altered, destroyed, or corrupted in an unauthorized manner during storage or transmission.

  • Protects against unauthorized modification.
  • Often achieved using hashing algorithms and digital signatures.
  • Crucial for trustworthy transactions and communications.

Memory trick: CIA: Confidentiality, Integrity, Availability – plus Non-repudiation.

More Cryptography questions