ISC2 CC Security Principles Practice Question
A junior security administrator at a hospital is told that only nurses and physicians on the current shift should be able to view patient records, and that records must be protected from disclosure to anyone else. Which security principle is this requirement primarily enforcing?
⚠ Common exam trap
The trap here is assuming that any access control example must be about availability because authorized users need access, when the requirement actually focuses on preventing unauthorized disclosure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
The requirement limits access to patient records so only authorized on-shift nurses and physicians can view them, which is a disclosure control. Confidentiality is the security principle that prevents information from being disclosed to unauthorized individuals. Integrity addresses unauthorized changes, availability addresses timely access, and non-repudiation addresses proof of actions, so confidentiality is the correct principle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confidentiality
Why this is correct
Confidentiality ensures information is not disclosed to unauthorized individuals, entities, or processes. Restricting patient record access to on-shift nurses and physicians directly limits disclosure to authorized parties, which is the core of confidentiality. This scenario is about preventing unauthorized viewing, not about keeping data accurate or available, so confidentiality is the principle being enforced.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation provides proof of the origin of data or an action, preventing a party from denying having performed it. The scenario does not involve proving who viewed or changed a record; it only restricts viewing to authorized on-shift personnel. Non-repudiation would require audit logs or digital signatures proving an action occurred, which is not described in this requirement.
- ✗
Integrity
Why it's wrong here
Integrity focuses on protecting information from unauthorized modification or destruction, ensuring data remains accurate and complete. In this scenario, the concern is who may view patient records, not whether the records have been altered. While integrity protections also matter in healthcare, the stated requirement about limiting viewing to on-shift staff is a disclosure restriction, so integrity is not the primary principle here.
- ✗
Availability
Why it's wrong here
Availability ensures systems and data are accessible to authorized users when needed. The scenario does not describe downtime, outages, or access failures; it describes limiting who can view records. Availability would apply if the hospital needed patient records accessible during an emergency, but the requirement here is about preventing unauthorized disclosure, making availability incorrect for this scenario.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Non-repudiation
Non-repudiation is a security principle that ensures a party in a digital transaction cannot deny their involvement or the authenticity of their digital signature.
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.