About this interactive
The CIA triad lists integrity as one of three concerns, and some people fold authenticity and non-repudiation into it. The lesson keeps them apart, using an email from Susan to David, and this activity asks you to do the same with new problems.
Integrity is about the message itself: when David opens it, it is complete and exactly what Susan sent. An on-path attacker who changes the meeting time, cuts a paragraph or swaps a link has broken integrity, even though the message really did start with Susan.
Authenticity is about who sent it. An outsider who sends David a message pretending to be Susan has broken authenticity, even if not a single word was altered on the way, because the words were never hers.
Non-repudiation is about what can be denied later. Susan should not be able to say she never sent the message, and David should not be able to say he never received it. Read receipts, and making the reader sign in before the message opens, are two of the older answers the lesson mentions.
Three questions sort every item. Was the message changed or cut on the way? Integrity. Is it really from the person it claims? Authenticity. Could someone deny their part afterwards? Non-repudiation. The technology answers come next in the module: hashing for integrity, certificates and PKI for authenticity, and digital signatures, which cover both.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →