Courseiva
mediumMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: A company's security policy states that all…

A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Unauthorized disclosure

Encryption at rest and in transit primarily protects confidentiality by preventing unauthorized access to data. Option B (Unauthorized disclosure) is correct. Option A (Data tampering) relates to integrity, not confidentiality. Option C (Denial of service) relates to availability, which encryption does not directly address. Option D (Repudiation) concerns non-repudiation, which encryption alone does not ensure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data tampering

    Why it's wrong here

    While encryption can hinder tampering, it is not the primary control; integrity checks like hashing are more direct.

  • Unauthorized disclosure

    Why this is correct

    Encryption prevents unauthorized parties from reading the data, thus preventing disclosure.

  • Denial of service

    Why it's wrong here

    Denial of service attacks target availability, not confidentiality.

  • Repudiation

    Why it's wrong here

    Repudiation is addressed by non-repudiation mechanisms like digital signatures.

About these practice questions

Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?

easy
  • A.Integrity
  • B.Authentication
  • C.Confidentiality
  • D.Availability

Why C: Encryption prevents unauthorized access to data, thereby maintaining confidentiality. Option A (Integrity) is wrong because while encryption can support integrity through hashing, its primary role is confidentiality. Option B (Authentication) is wrong because encryption alone does not verify identity; authentication requires separate mechanisms like digital signatures. Option D (Availability) is wrong because encryption does not ensure data is accessible; it protects data from unauthorized access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.