mediumMultiple Choice
Integrity: Missing Patches on Classified Server
A company wants to ensure that a message received was not altered in transit. Which principle is of primary concern?
⚠ Common exam trap
It's easy for candidates to confuse integrity with authentication or confidentiality; candidates often think that encryption (confidentiality) also guarantees no alteration, but encryption alone does not detect changes without an integrity mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrity
Integrity ensures that data has not been altered or tampered with during transmission. In the context of a received message, integrity guarantees that the message content remains exactly as sent by the originator. This is typically achieved using cryptographic hash functions or message authentication codes (MACs) that detect any modification. Thus, integrity is the primary concern when verifying that a message was not altered in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Availability
Why it's wrong here
Availability concerns timely access to data and systems, not detecting modification in transit. It is tempting because message delivery feels availability-related, and availability would be correct if the requirement were ensuring the message arrives when needed despite outages or denial-of-service.
- ✗
Authentication
Why it's wrong here
Authentication verifies the sender's identity, not that the message content remained unaltered. It is tempting because both rely on cryptographic mechanisms, and authentication would be correct if the requirement were confirming the message genuinely originated from the claimed sender.
- ✗
Confidentiality
Why it's wrong here
Confidentiality prevents unauthorised disclosure, not undetected alteration. It is tempting because both are protected by cryptography, and confidentiality would be correct if the requirement were keeping message contents secret from eavesdroppers rather than verifying they were unchanged.
- ✓
Integrity
Why this is correct
Integrity guarantees that data remains unaltered from sender to receiver, directly satisfying the requirement that a received message was not modified in transit. Cryptographic hashes and digital signatures detect any tampering, whereas confidentiality (encryption) and availability address different concerns entirely.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.