ISC2-CC - Security Principles (26% of the exam) - Section 1.1

Understand the security concepts of information assurance, including confidentiality, integrity, availability, authentication, non-repudiation, and privacy.

Define the CIA triad - confidentiality, integrity, and availability - as the three pillars that every security control ultimately serves, and recognise authentication, non-repudiation, and privacy as the supporting assurances. Distinguish the methods of authentication, including single-factor and multi-factor authentication (MFA), and identify which pillar a given control or breach affects.

CIA triadConfidentialityIntegrityAvailabilityMulti-factor authentication

Practice question for this objective

Free sampleSecurity Principleseasy

A training officer at a clinic explains that one member of the CIA triad is about making sure information is not disclosed to people or systems that have no authorisation to see it. Which member of the triad does this description define?

  • AConfidentiality, because it limits disclosure of information to those parties that have been properly authorised to access it. Correct
  • BIntegrity, because it keeps stored records accurate and unaltered by anyone who lacks the proper authorisation to change them.
  • CAvailability, because it keeps information reachable so that authorised users can obtain it whenever they legitimately need it.
  • DNon-repudiation, because it prevents a party from denying that it accessed or disclosed a given piece of information.
Confidentiality is the CIA triad property that prevents disclosure of information to unauthorised people or systems. Confidentiality restricts who can view data, so its purpose is to keep information from being disclosed to parties that lack authorisation, which distinguishes it from integrity and availability.

Why A is correct: Confidentiality is the triad property that prevents disclosure of information to unauthorised people or systems, which is exactly what the description states.

Why B is wrong: Integrity is tempting because unauthorised change is also a concern, but integrity concerns accuracy and prevention of alteration, not the prevention of disclosure that the description names.

Why C is wrong: Availability sounds relevant because it also involves authorised users, but it addresses timely access to data rather than stopping unauthorised parties from seeing it.

Why D is wrong: Non-repudiation is tempting through its link to accountability, but it proves that an action occurred rather than preventing disclosure to unauthorised parties.

See more ISC2-CC practice questions, answers explained.

Exam traps in Security Principles

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • Confidentiality, keeping order details hidden from unauthorised outsiders

    Why it is wrong: Confidentiality protects data from disclosure, which is valuable, but the customers here can already be trusted to see their own orders. The failure is that the service is unreachable, not that data leaked, so this is not the property in question.

  • A stricter password policy, forcing longer and more complex passphrases

    Why it is wrong: Stronger password rules make guessing harder and are worthwhile, but a password already exposed in a breach is compromised regardless of its complexity. A single factor still lets an attacker in, so this does not solve the problem.

  • Privacy concerns keeping systems running for authorised users, whereas confidentiality concerns proving that a message truly came from its stated sender.

    Why it is wrong: This conflates privacy with availability and confidentiality with non-repudiation, so neither half matches the intended concepts.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.