200-201 Security Concepts Practice Question
A security analyst at a financial services company is reviewing the organization's security program. The CISO wants to ensure that the confidentiality, integrity, and availability of information assets are protected by administrative, physical, and technical controls. Which security concept is the CISO describing?
⚠ Common exam trap
Test-takers frequently confuse the CIA triad with the AAA framework because both use three-letter acronyms and relate to security, but only the CIA triad describes confidentiality, integrity, and availability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CIA triad, which defines the three core objectives of information security that controls must protect.
The scenario names confidentiality, integrity, and availability as the properties controls must protect. These three objectives form the CIA triad, the foundational model of information security. Administrative, physical, and technical controls are all implemented to preserve these properties, so the concept described is the CIA triad rather than an access framework, a network model, or a single control principle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AAA framework, which governs authentication, authorization, and accounting for user access.
Why it's wrong here
AAA describes access control functions: authentication verifies identity, authorization determines permissions, and accounting logs activity. It does not describe protecting confidentiality, integrity, and availability. While AAA is part of a security program, the scenario specifically names the three objectives of C/I/A, not the access control framework, so AAA is not the concept being described here.
- ✗
The OSI model, which defines seven layers of network communication used to design secure protocols.
Why it's wrong here
The OSI model is a reference framework for network communication across seven layers. It helps analysts understand where attacks occur and where controls operate, but it does not define confidentiality, integrity, and availability as objectives. The scenario describes the core security objectives, not a layered networking model, so OSI is not the correct concept.
- ✓
The CIA triad, which defines the three core objectives of information security that controls must protect.
Why this is correct
The CIA triad is exactly what the CISO describes: confidentiality, integrity, and availability are the three foundational objectives of information security. Administrative, physical, and technical controls are implemented specifically to protect these three properties of information assets. This aligns with the Cisco CyberOps objective of understanding the core security principles that guide the design of a security program.
- ✗
The principle of least privilege, which restricts users to only the access required to perform their jobs.
Why it's wrong here
Least privilege is an access control principle that limits user rights to the minimum necessary. It supports confidentiality and integrity but is only one control, not the overarching concept covering all three objectives. The scenario explicitly names confidentiality, integrity, and availability as the properties to protect, which is the definition of the CIA triad, not least privilege.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.