Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy
A cybersecurity analyst is reviewing a company's data handling policies. The analyst notes that sensitive customer information, such as credit card numbers, is routinely stored in plain text on internal file servers. Which fundamental cybersecurity principle is being violated by this practice?
- AConfidentiality
- BAvailability
- CNon-repudiation
- DIntegrity
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Storing sensitive data in plain text directly violates the principle of confidentiality, which aims to prevent unauthorized disclosure of information. Encryption or other access controls should be in place.
Why the other options are wrong
- B. Availability ensures that authorized users can access information when needed, which is not directly impacted by plain-text storage.
- C. Non-repudiation provides assurance that a party cannot deny an action, which is unrelated to plain-text storage of sensitive data.
- D. Integrity ensures that data has not been altered or destroyed in an unauthorized manner, which is not the primary concern here.
Confidentiality
The principle that prevents unauthorized disclosure of information, ensuring that only authorized individuals or systems can access sensitive data.
- Protects against unauthorized data access
- Often implemented through encryption and access controls
- A core component of the CIA triad
Memory trick: CIA: Confidentiality, Integrity, Availability – keeping secrets, keeping true, keeping there.