Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A company's security policy states that all…

A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?

⚠ Common exam trap

Many exam-takers confuse encryption with other security goals like integrity or availability; candidates might think encryption also prevents tampering or repudiation, but it primarily ensures confidentiality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unauthorized disclosure

Encryption at rest and in transit protects data confidentiality by rendering it unreadable to unauthorized parties, directly mitigating unauthorized disclosure. Encryption ensures that even if data is intercepted or accessed, it cannot be understood without the decryption key. This control is a fundamental safeguard against data breaches and privacy violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data tampering

    Why it's wrong here

    Encryption at rest and in transit protects confidentiality, preventing unauthorised disclosure; tampering concerns integrity, which encryption alone does not guarantee without hashing or signatures. Data tampering is addressed by integrity controls such as MACs, digital signatures and checksums, not by ciphering the data.

  • ✓

    Unauthorized disclosure

    Why this is correct

    Encryption at rest and in transit directly counters unauthorised disclosure by rendering intercepted or exfiltrated data unreadable without decryption keys. This satisfies the policy's confidentiality requirement, addressing the threat of data being read by parties lacking authorisation, whether during network transmission or while stored on disk.

  • ✗

    Denial of service

    Why it's wrong here

    Denial of service targets availability by exhausting resources; encryption neither prevents nor mitigates flooding, and may add processing overhead. Availability is addressed through redundancy, rate limiting and DDoS protection. Encryption addresses confidentiality, so it is irrelevant to this threat model.

  • ✗

    Repudiation

    Why it's wrong here

    Repudiation concerns denying that an action occurred, countered by logging, digital signatures and audit trails proving origin and integrity. Encryption protects confidentiality of data at rest and in transit; it does not by itself bind a sender to a message. Non-repudiation requires cryptographic proof of origin.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?

easy
  • A.Integrity
  • B.Authentication
  • ✓ C.Confidentiality
  • D.Availability

Why C: Encryption protects data confidentiality by ensuring that only authorized parties can read the data. Whether at rest (stored on disk) or in transit (moving across networks), encryption renders data unreadable to unauthorized users, directly addressing the confidentiality aspect of the CIA triad. Integrity, authentication, and availability are separate concerns not primarily addressed by encryption alone.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.