NivaarExam PrepOfficial exam papers ↗

19-Soft-B3 Security · December 2016

Question 7 of 7: The CIA Triad — Confidentiality, Integrity, and Availability

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams, December 2016 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.

Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Stream/Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 10 (Key Management, Diffie–Hellman, RSA), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow), Ch. 1 (Security Concepts — CIA Triad); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control), Ch. 1 (Security Concepts).

Question 7: The CIA Triad — Confidentiality, Integrity, and Availability (20 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Part a) — identifying the violated property. The three core security properties (the CIA triad) are: confidentiality (information is disclosed only to authorized parties), integrity (information and systems are modified only in authorized ways and remain accurate/complete), and availability (authorized users can access information and systems when needed). Copying the password file to a remote system discloses its contents to a party never authorized to see it, without altering the original file or denying anyone's access to the system — this is a pure confidentiality violation. (It is also frequently a stepping stone to a later integrity violation, once the attacker cracks the copied hashes and uses the recovered credentials to log in and modify data, but the act described — the copy itself — violates confidentiality only.)

Part b) — examples of the other two violations. An integrity violation: an attacker who has gained write access to the same system alters entries in a financial ledger or modifies a compiled binary on a distribution server to insert malicious code — the data or system is changed in a way its owner never authorized, with no need for the attacker to have read anything sensitive. An availability violation: an attacker floods the system with traffic in a denial-of-service (DoS) attack, or simply deletes/encrypts the password file (ransomware) so legitimate administrators can no longer authenticate users at all — the information and service still "belong" to their rightful owners, but authorized use is prevented.

It is worth noting that a single incident can breach more than one property over time even though each individual action maps to exactly one. In this scenario, the confidentiality breach (copying the password file) is often only the opening move: once the attacker cracks the recovered hashes offline, using them to log in as a legitimate user and quietly alter records is a separate, subsequent integrity violation, and using that same access to lock out the real account holder or shut down the service is a separate, subsequent availability violation. Distinguishing the three at the moment each act occurs — rather than lumping "the attack" together as one undifferentiated event — matters operationally, because the appropriate incident response differs for each: a confidentiality breach calls for forced credential resets and notification of affected users, an integrity breach calls for restoring from a trusted backup and auditing what changed, and an availability breach calls for restoring service and hardening against the specific denial mechanism used.

Back to the paper →