FC0-U71 Security Practice Question
Which of the following best describes the 'Confidentiality' component of the CIA triad?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data is accessible only to authorized users
Confidentiality ensures that data is not accessed by unauthorized individuals. Integrity protects data from unauthorized modification, and availability ensures data is accessible when needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Systems are operational when needed
Why it's wrong here
Confidentiality concerns preventing unauthorised disclosure of data through encryption, access controls and classification. Availability, not confidentiality, covers systems being operational when needed, so this describes the wrong CIA component. It tempts because uptime and service continuity are genuine security concerns, but they belong to availability.
- ✓
Data is accessible only to authorized users
Why this is correct
Confidentiality ensures data is disclosed only to authorised users, enforced through encryption, access controls and authentication. This directly matches the stem's requirement that information remains inaccessible to unauthorised parties, distinguishing it from Integrity, which concerns accuracy, and Availability, which concerns timely access.
- ✗
Data is encrypted at rest
Why it's wrong here
Encryption at rest is one control that supports confidentiality, not the component itself, which concerns ensuring data is accessible only to authorised parties. It is tempting because encryption is commonly deployed for confidentiality, but the definition describes a mechanism rather than the principle.
- ✗
Data is not modified without authorization
Why it's wrong here
Preventing unauthorised modification describes integrity, not confidentiality. It is tempting because both are CIA triad components and authorisation appears in each, but the axis differs: integrity governs alteration of data, whereas confidentiality governs disclosure to unauthorised parties.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following best describes the principle of confidentiality in the CIA triad?
easy- A.Systems are accessible when needed
- B.Ensuring data is backed up regularly
- C.Data is not altered unexpectedly
- ✓ D.Preventing unauthorized access to data
Why D: Confidentiality in the CIA triad means ensuring that data is only accessible to authorized parties, i.e., preventing unauthorized access or disclosure. Option D directly captures this definition. The other options describe availability (A), a backup practice that supports availability/integrity (B), and integrity (C).
Variation 2. Which element of the CIA triad is primarily concerned with ensuring that data is not accessed by unauthorized individuals?
easy- ✓ A.Confidentiality
- B.Authentication
- C.Availability
- D.Integrity
Why A: Confidentiality is the CIA triad element that ensures data is only accessible to authorized individuals, typically enforced through encryption, access controls, and authentication mechanisms. It directly addresses the concern of preventing unauthorized access or disclosure. Integrity concerns data accuracy, and availability concerns uptime — neither addresses unauthorized access.
Variation 3. Which of the following best describes the principle of confidentiality in the CIA triad?
easy- A.Data is not altered unexpectedly
- B.Systems are accessible when needed
- C.Ensuring data is backed up regularly
- ✓ D.Preventing unauthorized access to information
Why D: Confidentiality in the CIA triad means ensuring information is not disclosed to unauthorized individuals, entities, or processes — i.e., preventing unauthorized access to information. It is enforced through encryption, access controls, and authentication. The scenario's phrasing 'preventing unauthorized access to information' is the textbook definition of confidentiality.
Variation 4. Which component of the CIA triad ensures that data cannot be modified by unauthorized users?
easy- ✓ A.Integrity
- B.Authentication
- C.Availability
- D.Confidentiality
Why A: Integrity, the 'I' in the CIA triad, specifically ensures that data remains accurate, complete, and unaltered unless modified by authorized parties. It protects against unauthorized modification, deletion, or corruption, whether the data is at rest, in transit, or in use. Authentication verifies identity, availability ensures access, and confidentiality prevents unauthorized disclosure—none of these directly address modification prevention.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.