ISC2 CC Security Principles Practice Question
A hospital's IT department is designing a new electronic health record system. The security architect proposes that all patient records be encrypted both at rest and in transit, and that access be restricted based on job roles. Which security principle is the architect primarily addressing?
⚠ Common exam trap
Test-takers frequently confuse the CIA triad components by assuming that any security control automatically addresses all three, rather than identifying the specific principle targeted by encryption and access controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
The architect's measures—encrypting patient records at rest and in transit and restricting access by job roles—are classic controls for protecting confidentiality. Confidentiality focuses on preventing unauthorized disclosure of information. While integrity and availability are also part of the CIA triad, the scenario's emphasis on encryption and access restrictions points specifically to confidentiality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confidentiality
Why this is correct
Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encrypting patient records at rest and in transit, combined with role-based access controls, directly prevents unauthorized viewing or exposure of sensitive health data. This aligns with the architect's goal of protecting patient information from improper disclosure, making confidentiality the principle being addressed.
- ✗
Availability
Why it's wrong here
Availability ensures timely and reliable access to information and systems by authorized users. While encryption and access controls could indirectly affect availability if misconfigured, the architect's stated measures are aimed at preventing unauthorized disclosure, not at ensuring the system remains accessible during failures or attacks. Therefore, availability is not the primary principle being addressed.
- ✗
Integrity
Why it's wrong here
Integrity ensures that information is accurate, complete, and protected from unauthorized modification. Encryption and role-based access can support integrity, but the scenario emphasizes preventing unauthorized viewing of patient records, which is a confidentiality concern. The architect did not mention checksums, digital signatures, or change controls that would directly ensure integrity.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation ensures that a party cannot deny having performed an action, often achieved through digital signatures and audit logs. The measures described—encryption and role-based access—do not provide proof of origin or prevent denial of actions. Thus, non-repudiation is not the principle the architect is addressing in this scenario.
Go deeper
Related to this question
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.