ITPEC FE Morning April 2023 Question 37

Source exam: ITPEC FE Morning April 2023Topic: Security

ITPEC FE Morning April 2023 — Question 37 of 80

Confidentiality violation (CIA triad) — identifying which attack violates confidentiality.

Confidentiality means preventing unauthorized access to information. Among the CIA triad:
- Confidentiality — unauthorized disclosure of information

- Integrity — unauthorized modification or destruction of information

- Availability — disruption of access to information or systems

Tricking a user into providing personal information to a fake website (phishing) causes unauthorized disclosure of private data, which is a violation of confidentiality.

Answer: (d)

Why not others:
- (a) DDoS (generating fake heavy traffic) disrupts access → violation of availability

- (b) Hardware destruction due to voltage failure destroys data/systems → violation of availability

- (c) Destroying ciphertext of confidential information → violation of integrity

Key rule: Confidentiality = unauthorized access/disclosure; Integrity = unauthorized modification/destruction; Availability = disruption of access to services.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.