Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsHard
A financial institution is implementing a new system to process high-value transactions. Regulators require assurance that if a dispute arises, it can be definitively proven who initiated a specific transaction and that the transaction details have not been altered. Which security principle is primarily addressed by this requirement?
- AConfidentiality
- BIntegrity
- CAvailability
- DNon-repudiation
Show answer & explanationAnswer & explanation
Correct answer: D. Non-repudiation
Non-repudiation ensures that a party cannot deny having performed an action or made a statement. In this scenario, it is critical to definitively prove who initiated a transaction (preventing denial of origin) and that the details haven't been altered (preventing denial of content), which directly aligns with non-repudiation.
Why the other options are wrong
- A. Confidentiality protects data from unauthorized disclosure, which is important but not the core requirement of proving origin/alteration.
- B. Integrity ensures data has not been altered, but non-repudiation adds the 'who did it' and 'can't deny it' aspects beyond just data consistency.
- C. Availability ensures that systems and data are accessible when needed, which is not the primary focus here.
Non-repudiation
The assurance that someone cannot deny the validity of something. In cybersecurity, it ensures that a party cannot deny having performed an action (e.g., sending a message, initiating a transaction) and that the data has not been altered.
- Prevents denial of origin of data or action.
- Prevents denial of receipt of data or action.
- Often achieved through digital signatures and logging.
Memory trick: Remember 'CAN't Deny' for Non-repudiation.