ITPEC FE Morning October 2022 Question 35
ITPEC FE Morning October 2022 — Question 35 of 80
CIA Triad — Integrity Attack — identify which attack targets data integrity.
CIA triad:
- Confidentiality — unauthorized disclosure of information
- Integrity — unauthorized modification of information
- Availability — disruption of access to information
Website defacement = attacker modifies web content without authorization → integrity attack.
Why not others:
- (a) DDoS — floods a service to make it unavailable → availability
- (b) Phishing — tricks users into revealing credentials → confidentiality
- (c) Shoulder surfing — visually spying on someone's screen/keyboard → confidentiality
Key rule: If data is changed without permission, it's an integrity attack. If data is leaked, it's confidentiality. If service is disrupted, it's availability.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.