An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?
Unencrypted email content is readable by anyone capturing the traffic, so unauthorised parties gain access to information they should not see. Confidentiality is the goal protecting data from disclosure, making it the property directly breached; integrity and availability remain intact.
Why this answer
Confidentiality ensures that data is only readable by authorized parties. When an attacker captures unencrypted email traffic in Wireshark and reads the contents, the confidentiality of the email is directly compromised because the data was exposed in plaintext to an unauthorized party.
Exam trap
CC often tests whether candidates can distinguish confidentiality (secrecy/reading) from integrity (modification) and non-repudiation (proof of origin) — eavesdropping is always a confidentiality violation, not integrity.
How to eliminate wrong answers
Option A is wrong because integrity refers to data being unaltered — the attacker read the email but did not necessarily modify it, so integrity is not the primary goal compromised. Option B is wrong because availability refers to data/services being accessible — reading traffic does not deny access. Option C is wrong because non-repudiation ensures a sender cannot deny sending a message — it is about proof of origin, not secrecy, and is not directly violated by passive eavesdropping.