~/ learn/ comp-400/ cards/ The two goals the triad leaves out
1 of 7

A bank keeps a tamper-evident log that ties every transfer instruction to the individual credential that submitted it, from which host and at what time, so that a customer cannot later deny having issued one. Which security goal is that log serving?

A bank keeps a tamper-evident log that ties every transfer instruction to the individual credential that submitted it, from which host and at what time, so that a customer cannot later deny having issued one. Which security goal is that log serving?

Answer

Accountability

Options - A. Accountability - B. Authenticity - C. Integrity - D. Non-repudiation - E. Privacy Why - A. Correct — accountability is the requirement that whatever the system did be attributable back to exactly one acting entity, which is precisely what the log delivers. - B. Authenticity is verifying at the time of the transaction that the instruction genuinely came from who it claims. The log is about afterwards. - C. Integrity is about the instruction being unaltered. The log is tamper-evident to protect the *trace*, but the goal being served is the trace itself. - D. The near-miss, and the one most people pick. Non-repudiation is a *consequence* of accountability, not the goal — accountability is what makes it possible. - E. Privacy is the individual’s control over what is collected about them. A log that records everything they do is, if anything, in tension with it.

Stallings & Brown 5e ch1 §1.1

space flip · ← → navigate · esc to exit
NORMAL ~/memra/library/31a8ab80-f928-42df-b3a6-a0143a594089/flashcard utf-8 LF