hardMultiple Select
200-201 Practice Question: Which THREE are principles of the CIA triad?…
Which THREE are principles of the CIA triad? (Select three.)
⚠ Common exam trap
Cisco often tests the distinction between the CIA triad and other security principles like non-repudiation or accountability, leading candidates to mistakenly include them as part of the triad when they are separate concepts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
The CIA triad consists of Confidentiality, Integrity, and Availability, so options B, D, and E are correct. Confidentiality (B) ensures data is accessible only to authorized parties, typically enforced through encryption, access control lists, and authentication. Integrity (D) ensures data remains accurate and unaltered in transit or at rest, supported by hashing, checksums, and digital signatures. Availability (E) ensures systems and data are accessible to authorized users when needed, achieved through redundancy, backups, and DDoS mitigation. Non-repudiation (A) and accountability (C) are related security principles but are not part of the CIA triad; non-repudiation guarantees a party cannot deny an action, and accountability ties actions to identified entities, both often grouped under broader frameworks like the Parkerian hexad or AAA rather than the core CIA triad.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation is a separate security property proving an action occurred, not one of the CIA triad's confidentiality, integrity and availability. It tempts because it is a recognised security principle often listed alongside CIA, and would be the answer if the question asked for authentication or accountability goals rather than the triad itself.
- ✓
Confidentiality
Why this is correct
Confidentiality is a core CIA triad principle, ensuring data is accessible only to authorised parties. It satisfies the stem's requirement by protecting information from unauthorised disclosure through mechanisms such as encryption, access controls and data classification. Alongside integrity and availability, it forms the three foundational security objectives the question asks you to identify.
- ✗
Accountability
Why it's wrong here
Accountability supports non-repudiation and auditing, but the CIA triad comprises confidentiality, integrity, and availability only. It is tempting because accountability underpins security governance and logging, yet it belongs to complementary models such as AAA rather than the three CIA principles the question requests.
- ✓
Integrity
Why this is correct
Integrity is a core CIA triad principle, ensuring data remains accurate and unaltered unless changed by authorised processes. It satisfies the stem's requirement by naming one of the three foundational security objectives, alongside confidentiality and availability, that together guide information security practise and safeguard data against unauthorised modification.
- ✓
Availability
Why this is correct
Availability ensures systems and data remain accessible to authorised users when required, completing the CIA triad alongside confidentiality and integrity. It directly satisfies the stem's demand for a core CIA principle, covering uptime, redundancy and resilience against denial-of-service or hardware failure.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.