ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingHard
A security team is performing a penetration test against a new web application. They manage to gain unauthorized access to an administrative interface by exploiting a known vulnerability in a third-party library. After gaining access, they discover that the application logs user activities but fails to protect the integrity of these logs, allowing an attacker with administrative access to modify or delete them without detection. This secondary finding represents a failure in which security control objective?
- ANon-repudiation
- BIntegrity
- CConfidentiality
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: B. Integrity
The ability of an attacker to 'modify or delete' logs 'without detection' directly compromises the integrity of those logs. Integrity ensures that information is accurate, complete, and protected from unauthorized modification or destruction.
Why the other options are wrong
- A. Non-repudiation prevents denial of actions, but the core issue is the ability to change/delete logs undetected, impacting their trustworthiness (integrity).
- C. Confidentiality protects against unauthorized disclosure, not modification or deletion.
- D. Availability ensures resources are accessible when needed, which is not the primary issue here.
CIA Triad (Integrity)
Integrity, part of the CIA Triad, ensures that information is accurate, complete, and protected from unauthorized modification or destruction.
- Protects against unauthorized alteration or deletion
- Ensures data is trustworthy and reliable
- Often maintained through hashing, digital signatures, access controls
Memory trick: CIA: Confidentiality, Integrity, Availability.