An organization encrypts the customer database stored on its file server. Which security principle does this control primarily support?
Choose one.
Security controls map to CIA triad goals. Encryption is the classic confidentiality control because it renders data unreadable to anyone without the correct key.
Encrypting data at rest means that even if the database file is stolen or accessed by an unauthorized person, its contents remain unreadable. That is a protection against unauthorized disclosure, which is confidentiality. It does not keep the server online, log activity, or grant permissions.
- Identify what the control does: encryption makes data unreadable without a key.
- Ask which CIA goal is served when unauthorized people cannot read data.
- Preventing unauthorized disclosure is confidentiality.
- Confirm the distractors map elsewhere: backups map to availability, logs map to accounting, permissions map to authorization.
Exam tip: On the exam, map encryption to confidentiality, hashing to integrity, and backups or redundancy to availability.
CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.