nerdexam
Dell-EMC

E10-001 · Question #108

What are the three primary goals of information security?

The correct answer is B. Availability, confidentiality, and integrity. Information Security Framework The basic information security framework is built to achieve four security goals, confidentiality, integrity, and availability (CIA) along with accountability. This framework incorporates all security standards, procedures and controls, required…

Securing Storage Infrastructure

Question

What are the three primary goals of information security?

Options

  • AAuthenticity, repudiation, and accountability
  • BAvailability, confidentiality, and integrity
  • CAuthenticity, confidentiality, and accountability
  • DAvailability, authenticity, and confidentiality

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    80% (40)
  • C
    12% (6)
  • D
    2% (1)

Explanation

Information Security Framework The basic information security framework is built to achieve four security goals, confidentiality, integrity, and availability (CIA) along with accountability. This framework incorporates all security standards, procedures and controls, required to mitigate threats in the storage infrastructure Confidentiality: Provides the required secrecy of information and ensures that only authorized users have access to data. This requires authentication of users who need to access information. Data in transit (data transmitted over cables) and data at rest (data residing on a primary storage, backup media, or in the archives) can be encrypted to maintain its confidentiality. In addition to restricting unauthorized users from accessing information, confidentiality also requires to implement traffic flow protection measures as part of the security protocol. These protection measures generally include hiding source and destination addresses, frequency of data being sent, and amount of data sent. Integrity: Ensures that the information is unaltered. Ensuring integrity requires detection and protection against unauthorized alteration or deletion of information. Ensuring integrity stipulate measures such as error detection and correction for both data and systems. Availability: This ensures that authorized users have reliable and timely access to systems, data and applications residing on these systems. Availability requires protection against unauthorized deletion of data and denial of service. Availability also implies that sufficient resources are available to provide a service. Accountability: Refers to accounting for all the events and operations that take place in the data center infrastructure. The accountability service maintains a log of events that can be audited or traced later for the purpose of security.

Topics

#CIA triad#information security#confidentiality#integrity

Community Discussion

No community discussion yet for this question.

Full E10-001 Practice