TechKnowSurge
NIST NICE K1120 CompTIA Tech+ 6.4 ISC2 CC 1.1 NIST 800-53 SI-7
InteractiveSecurityFree

Integrity, Authenticity or Non-Repudiation?

Susan sends David a message. Sort each problem by the guarantee it is about: integrity, authenticity or non-repudiation.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

The CIA triad lists integrity as one of three concerns, and some people fold authenticity and non-repudiation into it. The lesson keeps them apart, using an email from Susan to David, and this activity asks you to do the same with new problems. Integrity is about the message itself: when David opens it, it is complete and exactly what Susan sent. An on-path attacker who changes the meeting time, cuts a paragraph or swaps a link has broken integrity, even though the message really did start with Susan. Authenticity is about who sent it. An outsider who sends David a message pretending to be Susan has broken authenticity, even if not a single word was altered on the way, because the words were never hers. Non-repudiation is about what can be denied later. Susan should not be able to say she never sent the message, and David should not be able to say he never received it. Read receipts, and making the reader sign in before the message opens, are two of the older answers the lesson mentions. Three questions sort every item. Was the message changed or cut on the way? Integrity. Is it really from the person it claims? Authenticity. Could someone deny their part afterwards? Non-repudiation. The technology answers come next in the module: hashing for integrity, certificates and PKI for authenticity, and digital signatures, which cover both.

What you'll learn

Aligned to

NIST NICE
K1120 Knowledge of Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation (CIAAN) principles and practices
CompTIA Tech+
6.4 Compare and contrast authentication, authorization, accounting, and non-repudiation concepts
ISC2 CC
1.1 Understand cybersecurity concepts
NIST 800-53
SI-7 Software, Firmware, and Information Integrity

Key terms

Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.
Non-repudiation
The assurance that a party cannot deny having sent or received a message or performed an action.
On-Path Attack
An attack in which the adversary positions themselves between two communicating devices to intercept, relay, or alter traffic; also called a man-in-the-middle attack.
Impersonation
A social engineering tactic in which an adversary poses as a trusted individual or authority figure to gain a victim's confidence and compliance.

Topics

Integrity Authenticity Non Repudiation Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →