easyMultiple Choice
200-201 Practice Question: Which principle ensures that a user cannot deny…
Which principle ensures that a user cannot deny having performed an action?
⚠ Common exam trap
Cisco often tests the distinction between accountability and non-repudiation, where candidates confuse logging/tracking (accountability) with cryptographic proof (non-repudiation), leading them to select 'Accountability' instead of 'Non-repudiation'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Non-repudiation
Non-repudiation ensures that a user cannot deny having performed an action, typically by using digital signatures or cryptographic mechanisms. In network security, this is often achieved through protocols like HMAC or digital certificates that bind an action to a specific identity, providing irrefutable proof. Without non-repudiation, a user could claim they never sent a message or executed a command, undermining audit trails and legal accountability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication
Why it's wrong here
Authentication verifies a claimed identity at login; it establishes who someone is but does not by itself prevent them later repudiating an action. It is tempting because identity is a prerequisite for non-repudiation, but authentication would be correct if the question asked how a user's identity is verified.
- ✗
Accountability
Why it's wrong here
Accountability ties actions to an identified subject through logging and audit trails, but it does not itself prevent a user from denying an action; non-repudiation, backed by cryptographic evidence, does. It is tempting because accountability and non-repudiation are closely related, but accountability would be correct if the question asked who is answerable for an action.
- ✗
Authorization
Why it's wrong here
Authorization determines what an authenticated subject is permitted to do; it grants or denies access and records nothing about proving who acted. It is tempting because access control is central to security, but authorization would be the answer if the question asked what limits a user's permitted actions after login.
- ✓
Non-repudiation
Why this is correct
Non-repudiation uses cryptographic evidence such as digital signatures and audit logs to prove an action originated from a specific party. It prevents that party from later denying having performed the action, which is precisely the guarantee the question describes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.