ITPEC FE Morning October 2022 Question 35

Source exam: ITPEC FE Morning October 2022Topic: Security

ITPEC FE Morning October 2022 — Question 35 of 80

CIA Triad — Integrity Attack — identify which attack targets data integrity.

CIA triad:
- Confidentiality — unauthorized disclosure of information

- Integrity — unauthorized modification of information

- Availability — disruption of access to information

Website defacement = attacker modifies web content without authorization → integrity attack.

Why not others:
- (a) DDoS — floods a service to make it unavailable → availability

- (b) Phishing — tricks users into revealing credentials → confidentiality

- (c) Shoulder surfing — visually spying on someone's screen/keyboard → confidentiality

Key rule: If data is changed without permission, it's an integrity attack. If data is leaked, it's confidentiality. If service is disrupted, it's availability.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.