How Does Message Attribution Work in Security Controls?

Security Principles & Controls

Which of the following allows for the attribution of messages to individuals?

  1. Adaptive identity
  2. Non-repudiation Source Reference Answer
  3. Authentication
  4. Access logs

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of non-repudiation versus authentication, with the common trap being confusion between verifying identity at login and legally binding proof of message origin.

This question tests the security principle of non-repudiation, which ensures message origin can be definitively attributed to an individual. The community overwhelmingly agrees that despite poor wording, digital signatures and audit trails provide the legal proof needed to prevent senders from denying their actions.

Candidates often select Authentication because both involve verifying identity, but authentication only confirms who is accessing a system at a given moment rather than providing cryptographic proof that ties a specific past message to its author.

Community Discussion (11 comments)

Yoez 👍 49
I can't understand the sentence. Bad question
123456789User 👍 12 Selected: B
Non-repudiation - provides proof of the origin. Prevents individuals from denying involvement in sending the message.
_thelastturtle 👍 3 Selected: D
Didnt understand the question
braveheart22 👍 3 Selected: B
The correct answer is B. Non-repudiation. Non-repudiation refers to the ability to ensure that a person or entity cannot deny having sent or received a message. It provides a way to attribute actions or messages to specific individuals, typically through mechanisms such as digital signatures or secure logging. This guarantees that the sender of the message cannot later claim they did not send it, offering legal and security assurances.
KelvinYau 👍 1 Selected: B
i don't understand this question.
deejay2 👍 1
Nevermind, attribution means acknowledgement. So, B is right.
deejay2 👍 1
If attribution means source, the answer is C.
dbrowndiver 👍 4 Selected: B
Attribution of Messages: By implementing non-repudiation, organizations can confirm the source of a message or transaction. This is essential for legal and security purposes, as it prevents individuals from denying their actions or communications. Digital Signatures: Commonly used in emails and transactions, digital signatures are a key component of non-repudiation, as they uniquely identify the sender and confirm the message's origin. Why it is the best choice is bc Non-repudiation directly addresses the need to attribute messages to individuals, ensuring accountability and trust in communications.
d4a5620 👍 7 Selected: B
The wording on this question is absolutely horrendous but the answer is B
Arshedconoco 👍 3
So true that the wording of this question is very bad
shady23 👍 8 Selected: B
B. Non-repudiation

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Non-repudiation is a core security principle designed specifically to prevent individuals from denying they sent or received a communication. It achieves attribution through mechanisms like digital signatures, timestamped logs, and public key infrastructure, which cryptographically bind a message to a unique sender. As noted in the discussion, this creates legally defensible evidence that accurately attributes actions or communications to specific entities. Without non-repudiation, organizations would lack the forensic trail required for compliance and incident response.

Why the Other Options Are Wrong

Adaptive identity focuses on continuous risk-based assessment during sessions rather than historical message attribution. Authentication validates credentials at login but does not inherently preserve proof of what was communicated later. Access logs record system events and user activity, but without cryptographic signing or secure hashing, they can be altered and do not provide strong legal attribution. These controls support security operations but fall short of the strict attribution requirement outlined in the question.

Community Comment Notes

Multiple candidates highlighted the poorly worded prompt, with several noting that attribution directly implies identifying the source of a message. Users like [2] and [4] correctly clarified that non-repudiation provides the necessary proof of origin to prevent denial. Others initially confused the term with authentication or access logging before realizing attribution requires immutable cryptographic verification. The consensus strongly reinforces that non-repudiation is the only option meeting the legal and technical definition of message attribution.

Official Reference

Exam Strategy

When encountering terms like attribution, proof of origin, or cannot deny, immediately associate them with non-repudiation rather than authentication. Remember that authentication answers who are you while non-repudiation answers can you prove you did it. Focus on the legal and cryptographic implications of each control during the exam.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide