Security+ ยท 1.0 General Security Concepts
Non-repudiation
Cryptographic evidence that an actor performed an action, such that they cannot later credibly deny it. Typically provided by digital signatures + tamper-proof logs.
How this shows up at NCAE
Audit logs (`/var/log/auth.log`, `journalctl`) give weak non-repudiation at NCAE. if red team gets root, they can doctor them. AIDE and immutable log shipping would give stronger guarantees.