CSSLP · Question #180
You are responsible for network and information security at a large hospital. It is a significant concern that any change to any patient record can be easily traced back to the person who made that ch
The correct answer is C. Non repudiation. The ability to definitively trace any change to a patient record back to the individual who made it, ensuring they cannot deny their actions, is known as non-repudiation.
Question
You are responsible for network and information security at a large hospital. It is a significant concern that any change to any patient record can be easily traced back to the person who made that change. What is this called?
Options
- AAvailability
- BConfidentiality
- CNon repudiation
- DData Protection
How the community answered
(23 responses)- B4% (1)
- C91% (21)
- D4% (1)
Why each option
The ability to definitively trace any change to a patient record back to the individual who made it, ensuring they cannot deny their actions, is known as non-repudiation.
Availability refers to ensuring that authorized users can access information and systems when needed, which is not the same as tracing actions.
Confidentiality refers to protecting information from unauthorized access or disclosure, which is distinct from proving who performed an action.
Non-repudiation ensures that an individual cannot legitimately deny having performed a specific action, such as making a change to a patient record. In a hospital setting, this is critical for accountability and auditing, proving the origin of an action to prevent false denials.
Data protection is a broad term encompassing many security principles, including confidentiality, integrity, and availability, but 'tracing changes back to a person' specifically points to non-repudiation.
Concept tested: Non-repudiation in security
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/confidentiality-integrity-availability#non-repudiation
Topics
Community Discussion
No community discussion yet for this question.