Courseiva
hardMultiple Select

200-201 Practice Question: Which THREE are principles of the CIA triad?…

Which THREE are principles of the CIA triad? (Select three.)

⚠ Common exam trap

Cisco often tests the distinction between the CIA triad and other security principles like non-repudiation or accountability, leading candidates to mistakenly include them as part of the triad when they are separate concepts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confidentiality

The CIA triad consists of Confidentiality, Integrity, and Availability, so options B, D, and E are correct. Confidentiality (B) ensures data is accessible only to authorized parties, typically enforced through encryption, access control lists, and authentication. Integrity (D) ensures data remains accurate and unaltered in transit or at rest, supported by hashing, checksums, and digital signatures. Availability (E) ensures systems and data are accessible to authorized users when needed, achieved through redundancy, backups, and DDoS mitigation. Non-repudiation (A) and accountability (C) are related security principles but are not part of the CIA triad; non-repudiation guarantees a party cannot deny an action, and accountability ties actions to identified entities, both often grouped under broader frameworks like the Parkerian hexad or AAA rather than the core CIA triad.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation is a separate security property proving an action occurred, not one of the CIA triad's confidentiality, integrity and availability. It tempts because it is a recognised security principle often listed alongside CIA, and would be the answer if the question asked for authentication or accountability goals rather than the triad itself.

  • ✓

    Confidentiality

    Why this is correct

    Confidentiality is a core CIA triad principle, ensuring data is accessible only to authorised parties. It satisfies the stem's requirement by protecting information from unauthorised disclosure through mechanisms such as encryption, access controls and data classification. Alongside integrity and availability, it forms the three foundational security objectives the question asks you to identify.

  • ✗

    Accountability

    Why it's wrong here

    Accountability supports non-repudiation and auditing, but the CIA triad comprises confidentiality, integrity, and availability only. It is tempting because accountability underpins security governance and logging, yet it belongs to complementary models such as AAA rather than the three CIA principles the question requests.

  • ✓

    Integrity

    Why this is correct

    Integrity is a core CIA triad principle, ensuring data remains accurate and unaltered unless changed by authorised processes. It satisfies the stem's requirement by naming one of the three foundational security objectives, alongside confidentiality and availability, that together guide information security practise and safeguard data against unauthorised modification.

  • ✓

    Availability

    Why this is correct

    Availability ensures systems and data remain accessible to authorised users when required, completing the CIA triad alongside confidentiality and integrity. It directly satisfies the stem's demand for a core CIA principle, covering uptime, redundancy and resilience against denial-of-service or hardware failure.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.