N10-009 Network Security Practice Question
A network administrator is configuring a new firewall rule set and wants to ensure that all remote administration traffic to the firewall itself is encrypted. The administrator plans to use SSH for command-line access. Which security principle is being applied when SSH is used instead of Telnet for firewall management?
⚠ Common exam trap
The trap here is assuming that because SSH provides integrity checking, the answer must be integrity, when the scenario's core requirement is keeping management traffic secret.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
Using SSH instead of Telnet for firewall management encrypts the entire session, protecting credentials and configuration commands from interception. This directly enforces confidentiality, as the primary goal is to prevent unauthorized reading of sensitive administrative traffic. Integrity, availability, and non-repudiation are separate security goals that SSH may partially support, but they are not the driving principle for this specific requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Integrity
Why it's wrong here
Integrity ensures data is not altered in transit, and SSH does provide message integrity checks. However, the primary reason to replace Telnet with SSH in this scenario is to protect the secrecy of credentials and commands, not just to detect tampering. While integrity is a benefit, the question asks for the security principle being applied by choosing SSH for encrypted management, which is confidentiality.
- ✓
Confidentiality
Why this is correct
SSH encrypts the entire session, including authentication credentials and commands, preventing eavesdroppers from reading sensitive management traffic. This directly upholds confidentiality by ensuring only authorized parties can view the data. Using Telnet would transmit everything in cleartext, violating confidentiality. The scenario specifically requires encrypted remote administration, which is a confidentiality control.
- ✗
Availability
Why it's wrong here
Availability ensures systems and data are accessible when needed. SSH does not inherently improve availability; in fact, misconfigured SSH can lock out administrators. The scenario focuses on encrypting remote administration traffic, which is about preventing unauthorized disclosure, not ensuring uptime. Therefore, availability is not the principle being applied here.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation provides proof of the origin and integrity of data, often using digital signatures. SSH can use host keys and user keys, but the scenario only requires encrypted command-line access, not cryptographic proof that an administrator performed an action. Non-repudiation is a stronger guarantee than what SSH alone typically provides for interactive sessions, so it is not the correct principle.
Go deeper
Related to this question
Learn chapter
VPN Types: Site-to-Site, Remote Access, SSL/TLS
Key term
Non-repudiation
Non-repudiation is a security principle that ensures a party in a digital transaction cannot deny their involvement or the authenticity of their digital signature.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
This N10-009 question is part of Courseiva's 472-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.