Network Security 14% Lesson 1 of 8

Lesson 4.1.1 — CIA Triad, Risk Terminology & Encryption

Avatar Of Asad IjazAsad Ijaz ·Sep 20, 2026 ·5 min read
13% through domain
Illustration Of A Three-Legged Stool With Padlock, Checkmark, And Clock Icons On Each Leg

Domain 4.0 | Network Security — 14% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain the CIA triad and why each of its three components matters for network security
  • Define and distinguish between risk, vulnerability, exploit, and threat
  • Explain encryption for data in transit versus data at rest
  • Describe why encryption alone doesn’t eliminate risk
  • Recognize common security terminology as it appears in practical scenarios

Key Terms

TermDefinition
ConfidentialityPreventing unauthorized parties from accessing or viewing data
IntegrityEnsuring data has not been altered, whether accidentally or maliciously
AvailabilityEnsuring authorized users can access systems and data when needed
VulnerabilityA weakness in a system that could potentially be exploited
RiskThe potential for loss or damage when a threat successfully exploits a vulnerability

Explanation

Starting Module 4: From Operations to Security

Security isn’t a separate layer bolted onto everything covered so far — it’s woven through concepts already introduced. The VPNs and jump boxes from the previous module exist specifically to protect confidentiality and control access; disaster recovery planning exists specifically to protect availability. This module makes that security dimension explicit, starting with the foundational vocabulary and concepts that everything else in Module 4 builds on.

The CIA Triad

The CIA triad — Confidentiality, Integrity, and Availability — describes the three core properties security work is meant to protect:

  • Confidentiality means preventing unauthorized parties from accessing or viewing data. Encryption, access controls, and the VPNs and jump boxes covered earlier all serve confidentiality directly.
  • Integrity means ensuring data hasn’t been altered, whether by accident (a corrupted file transfer) or by a malicious actor deliberately tampering with it. A message that arrives exactly as it was sent has maintained its integrity; one that’s been silently modified in transit has not.
  • Availability means ensuring authorized users can actually access systems and data when they need to. This is exactly what high availability designs and disaster recovery planning protect against losing — a system that’s perfectly confidential and unmodified but completely unreachable has still failed at its job.
Triangle Diagram Showing Confidentiality, Integrity, And Availability As The Three Core Properties Of The Cia Triad
How Confidentiality, Integrity, And Availability Together Define What Security Work Protects

These three properties sometimes pull in different directions. Locking a system down aggressively to maximize confidentiality can hurt availability if legitimate users end up unable to get their work done; a highly available system replicated across many locations can be harder to keep uniformly confidential. Good security design deliberately balances all three rather than maximizing just one.

Risk, Vulnerability, Exploit, and Threat: Untangling Related Terms

These four terms get used loosely in casual conversation, but they describe genuinely distinct concepts, and understanding how they relate to each other matters:

  • A vulnerability is a weakness in a system — an unpatched piece of software, a misconfigured firewall rule, a weak password policy. On its own, a vulnerability is just a latent condition.
  • A threat is something or someone capable of taking advantage of a vulnerability — an attacker, a piece of malware, even an environmental event like a fire.
  • An exploit is the specific method or tool actually used to take advantage of a vulnerability — a piece of code, a technique, a specific attack sequence.
  • Risk is the resulting potential for loss or damage when a threat successfully exploits a vulnerability — generally understood as a function of both likelihood (how probable is this) and impact (how bad would it be).
Diagram Showing How A Vulnerability, A Threat, And An Exploit Combine To Produce Risk
How A Vulnerability, A Threat, And An Exploit Combine To Produce Risk

A useful way to hold these together: a vulnerability exists whether or not anything ever happens to it; a threat is the “who or what” that could act on it; an exploit is the “how” they’d actually do it; and risk is the overall exposure that results from all three being present together.

Encryption: Protecting Confidentiality Two Ways

Encryption directly serves confidentiality, and it applies in two genuinely different contexts:

Data in transit refers to data actively moving across a network — between a client and a server, across a VPN tunnel, between two sites. Protecting data in transit is exactly what the encrypted tunnels in site-to-site and client-to-site VPNs and protocols like IPsec, both covered earlier in this course, are built to provide.

Data at rest refers to data sitting in storage — on a hard drive, in a database, in a backup file — with nothing actively transmitting it at that moment. Protecting data at rest typically means encrypting the storage itself, so that even if someone gains physical or unauthorized access to the storage medium, the data remains unreadable without the correct decryption key.

Diagram Comparing Encrypted Data Moving Across A Network Against Encrypted Data Sitting In Storage
How Encrypting Data In Transit Differs From Encrypting Data At Rest

Both matter because data faces different exposure at different points in its lifecycle — data can be intercepted while moving across a network even if it’s perfectly secured while stored, and it can be stolen directly from storage (a stolen laptop, a compromised backup) even if every network transmission along the way was properly encrypted.

Why Encryption Isn’t a Complete Solution

Encryption is a powerful tool, but it’s easy to over-rely on it as if it solved security by itself. Encryption protects confidentiality specifically — it does essentially nothing for availability, and it doesn’t eliminate the underlying vulnerability that might have let an attacker in before encryption ever became relevant. A denial-of-service attack that takes a service offline entirely isn’t stopped by encrypting that service’s data; a weak, easily guessed password that grants an attacker legitimate-looking access doesn’t get any harder to abuse just because the data behind that login is encrypted once they’re in.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A description of unauthorized access being prevented points to confidentiality; a description of ensuring data hasn’t been tampered with points to integrity; a description of systems staying reachable points to availability.
  • An unpatched piece of software sitting on a server, with nothing yet done to it, is a vulnerability, not a risk or a threat by itself.
  • Data actively crossing a network link is “in transit”; data sitting untouched on a disk or in a backup is “at rest” — the same dataset can be in either state at different points in time.
  • A scenario where data is confidential but the actual service hosting it is completely unreachable represents an availability failure, not a confidentiality one.

Common Exam Traps

  • Vulnerability, threat, exploit, and risk are not interchangeable terms, even though they’re often used loosely that way in everyday speech. Each describes a distinct piece of the overall picture.
  • Risk is a function of both likelihood and impact together, not just how bad an outcome would be. A high-impact but extremely unlikely scenario and a low-impact but very likely scenario can represent comparable overall risk.
  • Encrypting data in transit doesn’t automatically mean that same data is also encrypted at rest, and vice versa — these are two separate protections that need to be deliberately addressed independently.
  • The CIA triad’s three properties can genuinely conflict with each other. Don’t assume maximizing one (like confidentiality through aggressive lockdown) has no cost to the others.
  • Encryption addresses confidentiality specifically — it is not a general-purpose security fix. Don’t assume an encrypted system is therefore protected against availability attacks or vulnerabilities that grant access before encryption is even relevant.

Lesson 4.1.1 Practice Quiz — CIA Triad, Risk Terminology & Encryption

17 questions covering confidentiality/integrity/availability, risk/vulnerability/exploit/threat, and data in transit vs. at rest.

N10-009 · Domain 4.1
Question 1Plain
What does the "A" in the CIA triad stand for?
The CIA triad stands for Confidentiality, Integrity, and Availability.
Question 2Plain
What is a vulnerability?
A vulnerability is a weakness in a system — a latent condition, distinct from a threat, exploit, or risk.
Question 3Plain
What is data at rest?
Data at rest refers to data sitting in storage — on a disk, in a database, in a backup — with nothing actively transmitting it at that moment.
Question 4Choose Two
Which two statements correctly describe parts of the CIA triad? (Choose two.)
Confidentiality prevents unauthorized access; availability ensures authorized access when needed — integrity is instead about data not being altered, and confidentiality is not about uptime.
Question 5Choose Two
Which two statements about risk terminology are correct? (Choose two.)
A vulnerability is the weakness itself, and a threat is what could act on it — an exploit is the specific method used (distinct from the vulnerability), and risk is explicitly a function of both likelihood and impact.
Question 6Choose Two
Which two statements about encryption are correct? (Choose two.)
Encryption protects confidentiality, and data in transit vs. at rest genuinely need separate protection — encryption does not address availability threats or eliminate underlying vulnerabilities.
Question 7Scenario
A company wants to ensure that if their database backup files are physically stolen, the data on them remains unreadable. What should they implement?
Protecting stored backup files specifically calls for data at rest encryption — data in transit encryption alone wouldn't protect a stolen physical backup.
Question 8Scenario
A company wants to ensure that API traffic between a client and server can't be read if intercepted on the network. What should they implement?
Protecting traffic while it actively moves across the network is exactly what data in transit encryption addresses.
Question 9Scenario
A server has a known unpatched flaw, but no attacker has yet attempted to exploit it. How should this situation be described?
An unpatched flaw sitting unattacked is a vulnerability — a latent weakness — not yet an exploit or a realized incident.
Question 10Scenario
A DDoS attack takes a web server completely offline, even though the server's database is fully encrypted at rest. Which CIA triad property has been compromised?
Taking the server offline is an availability failure — the encryption protecting confidentiality had no bearing on whether the service stayed reachable.
Question 11Scenario
A security team evaluates a scenario by weighing how probable it is against how severe the consequences would be if it occurred. What are they calculating?
Weighing likelihood against impact together is exactly how risk is calculated.
Question 12Exhibit
Based on this security report entry, what term best describes what's being reported?
Security Report: System: WEB-SRV-04 Finding: Unpatched CVE-2026-XXXX present in web server software Status: No known exploitation attempts detected
An unpatched known flaw (CVE) with no exploitation attempts detected is exactly a vulnerability — the weakness itself, not yet an actual attack.
Question 13Exhibit
Based on this incident report, which part represents the exploit specifically?
Incident Report: Vulnerability: Unpatched CVE in VPN appliance firmware Threat Actor: External attacker group "APT-Group-X" Method Used: Publicly available proof-of-concept exploit code targeting the CVE
The proof-of-concept code is the specific method used to take advantage of the vulnerability — the exploit. The CVE itself is the vulnerability, and the attacker group is the threat.
Question 14Exhibit
Based on this configuration, what type of data protection is in place?
Security Config: API Gateway: TLS 1.3 enforced on all client-server connections Certificate: Valid, issued by internal CA
TLS enforced on active client-server connections protects data actively moving across the network — data in transit encryption.
Question 15Exhibit
Based on this configuration, what type of data protection is in place?
Security Config: Backup Server: AES-256 full disk encryption enabled Status: All stored backup files encrypted at the volume level
Full disk encryption on stored backup files is exactly data at rest encryption, protecting the data while it sits in storage.
Question 16Exhibit
Based on this incident timeline, which CIA triad property was compromised, despite the database remaining fully encrypted?
Incident Timeline: 10:00 — DoS attack begins against public web application 10:05 — Application becomes unreachable to all users Database encryption status throughout: AES-256, fully intact, never accessed by attacker
The application becoming unreachable is an availability compromise — the fully intact encryption shows confidentiality was never actually at risk in this specific incident.
Question 17Exhibit
Based on this risk matrix entry, what is being calculated?
Risk Matrix Entry: Scenario: Unpatched VPN appliance exposed to internet Likelihood: High Impact: Severe Resulting Score: Critical Risk
Combining likelihood and impact into a single resulting score is exactly how risk is calculated in a risk matrix.
📝

Summary

The CIA triad — Confidentiality, Integrity, and Availability — defines the three core properties network security work protects, and these properties can sometimes conflict with each other.

A vulnerability is a weakness, a threat is what could exploit it, an exploit is the specific method used, and risk is the resulting potential for loss when they combine — four distinct, related concepts.

Encrypting data in transit protects it while actively moving across a network; encrypting data at rest protects it while stored, and both are needed since data faces different exposure at each stage.

Encryption protects confidentiality specifically and does not address availability threats or eliminate the underlying vulnerabilities that might grant unauthorized access in the first place.

This lesson opens Module 4 (Network Security), building the vocabulary the rest of the module's lessons will rely on.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.