Domain 4.0 | Network Security — 14% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Explain the CIA triad and why each of its three components matters for network security
- Define and distinguish between risk, vulnerability, exploit, and threat
- Explain encryption for data in transit versus data at rest
- Describe why encryption alone doesn’t eliminate risk
- Recognize common security terminology as it appears in practical scenarios
Key Terms
| Term | Definition |
|---|---|
| Confidentiality | Preventing unauthorized parties from accessing or viewing data |
| Integrity | Ensuring data has not been altered, whether accidentally or maliciously |
| Availability | Ensuring authorized users can access systems and data when needed |
| Vulnerability | A weakness in a system that could potentially be exploited |
| Risk | The potential for loss or damage when a threat successfully exploits a vulnerability |
Explanation
Starting Module 4: From Operations to Security
Security isn’t a separate layer bolted onto everything covered so far — it’s woven through concepts already introduced. The VPNs and jump boxes from the previous module exist specifically to protect confidentiality and control access; disaster recovery planning exists specifically to protect availability. This module makes that security dimension explicit, starting with the foundational vocabulary and concepts that everything else in Module 4 builds on.The CIA Triad
The CIA triad — Confidentiality, Integrity, and Availability — describes the three core properties security work is meant to protect:
- Confidentiality means preventing unauthorized parties from accessing or viewing data. Encryption, access controls, and the VPNs and jump boxes covered earlier all serve confidentiality directly.
- Integrity means ensuring data hasn’t been altered, whether by accident (a corrupted file transfer) or by a malicious actor deliberately tampering with it. A message that arrives exactly as it was sent has maintained its integrity; one that’s been silently modified in transit has not.
- Availability means ensuring authorized users can actually access systems and data when they need to. This is exactly what high availability designs and disaster recovery planning protect against losing — a system that’s perfectly confidential and unmodified but completely unreachable has still failed at its job.

These three properties sometimes pull in different directions. Locking a system down aggressively to maximize confidentiality can hurt availability if legitimate users end up unable to get their work done; a highly available system replicated across many locations can be harder to keep uniformly confidential. Good security design deliberately balances all three rather than maximizing just one.
Risk, Vulnerability, Exploit, and Threat: Untangling Related Terms
These four terms get used loosely in casual conversation, but they describe genuinely distinct concepts, and understanding how they relate to each other matters:
- A vulnerability is a weakness in a system — an unpatched piece of software, a misconfigured firewall rule, a weak password policy. On its own, a vulnerability is just a latent condition.
- A threat is something or someone capable of taking advantage of a vulnerability — an attacker, a piece of malware, even an environmental event like a fire.
- An exploit is the specific method or tool actually used to take advantage of a vulnerability — a piece of code, a technique, a specific attack sequence.
- Risk is the resulting potential for loss or damage when a threat successfully exploits a vulnerability — generally understood as a function of both likelihood (how probable is this) and impact (how bad would it be).

A useful way to hold these together: a vulnerability exists whether or not anything ever happens to it; a threat is the “who or what” that could act on it; an exploit is the “how” they’d actually do it; and risk is the overall exposure that results from all three being present together.
Encryption: Protecting Confidentiality Two Ways
Encryption directly serves confidentiality, and it applies in two genuinely different contexts:
Data in transit refers to data actively moving across a network — between a client and a server, across a VPN tunnel, between two sites. Protecting data in transit is exactly what the encrypted tunnels in site-to-site and client-to-site VPNs and protocols like IPsec, both covered earlier in this course, are built to provide.Data at rest refers to data sitting in storage — on a hard drive, in a database, in a backup file — with nothing actively transmitting it at that moment. Protecting data at rest typically means encrypting the storage itself, so that even if someone gains physical or unauthorized access to the storage medium, the data remains unreadable without the correct decryption key.

Both matter because data faces different exposure at different points in its lifecycle — data can be intercepted while moving across a network even if it’s perfectly secured while stored, and it can be stolen directly from storage (a stolen laptop, a compromised backup) even if every network transmission along the way was properly encrypted.
Why Encryption Isn’t a Complete Solution
Encryption is a powerful tool, but it’s easy to over-rely on it as if it solved security by itself. Encryption protects confidentiality specifically — it does essentially nothing for availability, and it doesn’t eliminate the underlying vulnerability that might have let an attacker in before encryption ever became relevant. A denial-of-service attack that takes a service offline entirely isn’t stopped by encrypting that service’s data; a weak, easily guessed password that grants an attacker legitimate-looking access doesn’t get any harder to abuse just because the data behind that login is encrypted once they’re in.
Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- A description of unauthorized access being prevented points to confidentiality; a description of ensuring data hasn’t been tampered with points to integrity; a description of systems staying reachable points to availability.
- An unpatched piece of software sitting on a server, with nothing yet done to it, is a vulnerability, not a risk or a threat by itself.
- Data actively crossing a network link is “in transit”; data sitting untouched on a disk or in a backup is “at rest” — the same dataset can be in either state at different points in time.
- A scenario where data is confidential but the actual service hosting it is completely unreachable represents an availability failure, not a confidentiality one.
Common Exam Traps
- Vulnerability, threat, exploit, and risk are not interchangeable terms, even though they’re often used loosely that way in everyday speech. Each describes a distinct piece of the overall picture.
- Risk is a function of both likelihood and impact together, not just how bad an outcome would be. A high-impact but extremely unlikely scenario and a low-impact but very likely scenario can represent comparable overall risk.
- Encrypting data in transit doesn’t automatically mean that same data is also encrypted at rest, and vice versa — these are two separate protections that need to be deliberately addressed independently.
- The CIA triad’s three properties can genuinely conflict with each other. Don’t assume maximizing one (like confidentiality through aggressive lockdown) has no cost to the others.
- Encryption addresses confidentiality specifically — it is not a general-purpose security fix. Don’t assume an encrypted system is therefore protected against availability attacks or vulnerabilities that grant access before encryption is even relevant.
Lesson 4.1.1 Practice Quiz — CIA Triad, Risk Terminology & Encryption
17 questions covering confidentiality/integrity/availability, risk/vulnerability/exploit/threat, and data in transit vs. at rest.
N10-009 · Domain 4.1Summary
The CIA triad — Confidentiality, Integrity, and Availability — defines the three core properties network security work protects, and these properties can sometimes conflict with each other.
A vulnerability is a weakness, a threat is what could exploit it, an exploit is the specific method used, and risk is the resulting potential for loss when they combine — four distinct, related concepts.
Encrypting data in transit protects it while actively moving across a network; encrypting data at rest protects it while stored, and both are needed since data faces different exposure at each stage.
Encryption protects confidentiality specifically and does not address availability threats or eliminate the underlying vulnerabilities that might grant unauthorized access in the first place.
This lesson opens Module 4 (Network Security), building the vocabulary the rest of the module's lessons will rely on.



