Correct Answer: B
Explanation/Reference:
Explanation:
Non-repudiation is provided by applications such as PGP (Pretty Good Privacy). It is implemented in software and therefore run in the application layer.
Non-repudiation means that parties involved in a communication cannot deny having participated. It is a technique that assures genuine communication that cannot subsequently be refuted.
Implementing security at the application layer simplifies the provision of services such as non-repudiation by giving complete access to the data the user wants to protect.
Incorrect Answers:
A: Non-repudiation is implemented at application layer, not at the network layer.
C: Non-repudiation is implemented at application layer, not at the transport layer.
D: Non-repudiation is implemented at application layer, not at the data-link layer.
References:
Conrad, Eric, Seth Misenar and Joshua Feldman, CISSP Study Guide, 2nd Edition, Syngress, Waltham,
2012, p. 249