mediumMultiple Choice
ISC2 CC Practice Question: A company's security policy states that all…
A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?
⚠ Common exam trap
Many exam-takers confuse encryption with other security goals like integrity or availability; candidates might think encryption also prevents tampering or repudiation, but it primarily ensures confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized disclosure
Encryption at rest and in transit protects data confidentiality by rendering it unreadable to unauthorized parties, directly mitigating unauthorized disclosure. Encryption ensures that even if data is intercepted or accessed, it cannot be understood without the decryption key. This control is a fundamental safeguard against data breaches and privacy violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data tampering
Why it's wrong here
Encryption at rest and in transit protects confidentiality, preventing unauthorised disclosure; tampering concerns integrity, which encryption alone does not guarantee without hashing or signatures. Data tampering is addressed by integrity controls such as MACs, digital signatures and checksums, not by ciphering the data.
- ✓
Unauthorized disclosure
Why this is correct
Encryption at rest and in transit directly counters unauthorised disclosure by rendering intercepted or exfiltrated data unreadable without decryption keys. This satisfies the policy's confidentiality requirement, addressing the threat of data being read by parties lacking authorisation, whether during network transmission or while stored on disk.
- ✗
Denial of service
Why it's wrong here
Denial of service targets availability by exhausting resources; encryption neither prevents nor mitigates flooding, and may add processing overhead. Availability is addressed through redundancy, rate limiting and DDoS protection. Encryption addresses confidentiality, so it is irrelevant to this threat model.
- ✗
Repudiation
Why it's wrong here
Repudiation concerns denying that an action occurred, countered by logging, digital signatures and audit trails proving origin and integrity. Encryption protects confidentiality of data at rest and in transit; it does not by itself bind a sender to a message. Non-repudiation requires cryptographic proof of origin.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?
easy- A.Integrity
- B.Authentication
- ✓ C.Confidentiality
- D.Availability
Why C: Encryption protects data confidentiality by ensuring that only authorized parties can read the data. Whether at rest (stored on disk) or in transit (moving across networks), encryption renders data unreadable to unauthorized users, directly addressing the confidentiality aspect of the CIA triad. Integrity, authentication, and availability are separate concerns not primarily addressed by encryption alone.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.