Soru

Zorluk: OrtaCIA Triad & Core Security Concepts

During a routine audit, a system administrator discovers that an internal API service running on a web server had its configuration settings modified without authorization. While the service remained continuously reachable and no sensitive customer records were exposed or viewed by unauthorized parties, the altered configuration caused transaction logs to record invalid data. Which principle of the CIA triad was directly compromised in this scenario, and which security mechanism specifically protects against this type of breach?

  1. Integrity; protected by enforcing strict file access control lists and cryptographic hashing to detect and prevent unauthorized data alterations.Cevap
  2. B
    Availability; protected by implementing redundant load balancing across multiple active server nodes.
  3. C
    Confidentiality; protected by enforcing Transport Layer Security (TLS) payload encryption over TCP connection channels.
  4. D
    Authentication; protected by switching remote management traffic from RADIUS to TACACS+ for network hardware devices.

Cevap

Integrity was compromised, which is best protected by enforcing file access control lists and cryptographic hashing to prevent unauthorized alterations.
Integrity is the core security concept dedicated to ensuring data, configurations, and system resources remain unmodified and accurate unless explicitly changed by authorized users. Enforcing strict file permissions and verifying checksums or cryptographic hashes ensures files cannot be secretly altered.

Adım Adım Çözüm

1
Analyze the impact on system attributes based on the scenario metrics.
The service remained reachable (Availability intact) and data was not exposed to unauthorized viewers (Confidentiality intact), but service configuration and logs were altered without authorization.
Identifying which security boundary was crossed requires analyzing what stayed secure versus what was impacted.
2
Map the specific impact to the CIA triad pillars.
Unauthorized modification of data or settings directly violates Integrity.
Integrity guarantees that data has not been altered, tampered with, or corrupted by unauthorized entities.
3
Select the security control that directly preserves integrity.
Access control lists combined with cryptographic hashing maintain data integrity and detect unauthorized changes.
Hashing validates data consistency and file access permissions prevent unauthorized write operations.

Anahtar Kavram

CIA Triad Principles & Integrity Controls
Tahmini Süre:1m 15s
Bu soruyu puanla