Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

A hospital wants to ensure that patient records can only be viewed by authorized clinical staff, and that any modification to a record is traceable to the individual who made it. Which security principle directly supports both of these requirements?

⚠ Common exam trap

The trap here is assuming that any access-control principle, such as least privilege, also provides the audit trail needed to trace who changed a record.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accountability

The hospital needs two things: only authorized clinical staff can view records, and every modification is attributable to a person. Accountability supplies both, because actions are bound to authenticated identities and recorded in logs. Availability concerns uptime, non-repudiation concerns denying actions, and least privilege concerns permission scope, so none of them covers traceability as directly as accountability does.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation prevents a party from denying that an action occurred, which is valuable for disputes over a signed record or transaction. However, the hospital's requirements are narrower: only authorized staff may view records, and modifications must be traceable. Traceability is provided by accountability and logging, while non-repudiation is a stronger property typically tied to digital signatures and does not by itself limit viewing to clinical staff.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege limits each user to the minimum access needed to perform their duties, which helps restrict patient records to clinical staff. But it speaks only to the scope of permissions, not to recording which individual made a specific modification. The hospital's second requirement, traceability of changes, is met through accountability and audit logging rather than least privilege alone, so this choice covers only half the scenario.

  • ✗

    Availability

    Why it's wrong here

    Availability ensures that patient records remain accessible to authorized users when needed, for example during an emergency or a system outage. It addresses uptime and timely access rather than restricting who may view a record or tracing who changed it. The hospital's two stated requirements concern identity and traceability, so availability does not satisfy them even though it is a legitimate security goal.

  • ✓

    Accountability

    Why this is correct

    Accountability ties each action performed on patient records back to a specific authenticated identity, which is exactly what traceability of modifications requires. Because access is granted only to authenticated clinical staff and every change is logged against that identity, the hospital can both restrict viewing to authorized personnel and later determine who altered a record. It is the principle that makes the other controls enforceable.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.