Security+ Lesson

CIA And Non-Repudiation for Security+

Last updated: 6/10/2026

Short answer

CIA is a quick way to classify what security is trying to protect. Confidentiality is about secrecy and controlled disclosure. If a payroll spreadsheet is emailed to the wrong recipient, confidentiality is the main failure because unauthorized people can read sensitive data. Integrity is about trustworthiness and correctness. If an attacker changes a bank account number in a payment record or malware alters a system file, integrity is the main failure because the data or system state can no longer be trusted. Availability is about usable access.

Why it appears on the exam

SY0-701 1.2: Explain confidentiality, integrity, availability, and non-repudiation as core security goals and map each to clear examples.

Key concepts

Concept 1

Required terms

CIA: The confidentiality, integrity, and availability triad used to organize core security goals. Confidentiality: Keeping information from being viewed, copied, or disclosed by unauthorized people, systems, or processes. Integrity: Keeping data and systems accurate, complete, and protected from unauthorized or accidental alteration. Availability: Keeping systems, applications, and data reachable when authorized users need them.

Example

A contractor can open a confidential HR folder without approval. The best goal match is confidentiality because sensitive information is exposed to an unauthorized person.

Concept 2

How CIA And Non-Repudiation works

CIA is a quick way to classify what security is trying to protect. Confidentiality is about secrecy and controlled disclosure. If a payroll spreadsheet is emailed to the wrong recipient, confidentiality is the main failure because unauthorized people can read sensitive data. Integrity is about trustworthiness and correctness. If an attacker changes a bank account number in a payment record or malware alters a system file, integrity is the main failure because the data or system state can no longer be trusted. Availability is about usable access.

Example

A website database is modified so product prices are changed without authorization. The best goal match is integrity because records have been altered and may no longer be accurate.

Concept 3

Common confusion

Learners often treat every security failure as confidentiality because data is involved. The shortest correction is to ask what happened to the asset: exposed means confidentiality, changed means integrity, unavailable means availability, and denied action means non-repudiation.

Example

A ransomware incident prevents staff from opening patient scheduling records. The best goal match is availability because authorized users cannot access needed data or services.

Concept 4

What to recognize

Given a one-sentence incident, choose whether confidentiality, integrity, availability, or non-repudiation is most directly affected; Identify which part of CIA is supported by a simple control such as backups, access restrictions, validation checks, or redundancy; Distinguish non-repudiation from ordinary authentication or generic accountability in a short transaction scenario; Unfair targets: requiring public key infrastructure (PKI) mechanics, signature algorithms, certificate validation, key escrow, business continuity architecture, or risk calculations.

Example

A user later denies approving a funds transfer, but the system has a trustworthy record tying the approval to that user's verified action. The goal being supported is non-repudiation.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: A contractor can open a confidential HR folder without approval. because sensitive information is exposed to an unauthorized person. Which answer matches it?

Q2.Read this Security+ situation: A website database is modified so product prices are changed without authorization. because records have been altered and may no longer be accurate. What is the best match?

Q3.A security team needs to decide what this situation represents: A ransomware incident prevents staff from opening patient scheduling records. because authorized users cannot access needed data or services. Which option fits?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8