Soru

Zorluk: OrtaCIA Triad & Core Security Concepts

A financial institution requires a technical solution for transmitting executive financial reports across an internal network. The solution must guarantee that the recipient can verify the document was not altered in transit and prove conclusively which executive authored the document. Which of the following combinations of security principles and mechanisms best addresses these requirements?

  1. Integrity and Non-repudiation provided by asymmetric digital signaturesCevap
  2. B
    Confidentiality and Availability provided by symmetric AES-256 encryption
  3. C
    Authentication and Confidentiality provided by WPA3-Personal pre-shared keys
  4. D
    Availability and Integrity provided by Layer 2 frame encapsulation over TCP

Cevap

Integrity and Non-repudiation provided by asymmetric digital signatures
Asymmetric digital signatures satisfy both requirements. A cryptographic hash of the document ensures integrity by detecting any tampering in transit. Signing that hash with the sender's private key establishes non-repudiation, as only the holder of the corresponding key pair could have generated the signature.

Adım Adım Çözüm

1
Identify the key security goals from the scenario requirements
Requirement 1 (verifying data was not altered) maps to Integrity. Requirement 2 (indisputably proving author identity) maps to Non-repudiation.
Integrity protects against unauthorized modification, while Non-repudiation prevents an author from denying they created the data.
2
Analyze technical controls that support both principles simultaneously
Asymmetric digital signatures use a cryptographic hash for integrity and the signer's private key for non-repudiation.
A modified file changes the calculated hash value (failing integrity check), and only the private key owner could have produced the signature (enforcing non-repudiation).

Anahtar Kavram

CIA Triad & Core Security Concepts (Integrity and Non-repudiation)
Tahmini Süre:1m 30s
Bu soruyu puanla