ISC2 CC Security Principles Practice Question
A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?
⚠ Common exam trap
Test-takers frequently confuse integrity with authentication because both involve verification; candidates may think hashing authenticates the file's source, but it only proves the file has not changed since the baseline was taken.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrity
Hashing critical files and storing their hash values allows the administrator to later recompute the hash and compare it to the stored value. If the file contents change, the hash will differ, revealing unauthorized modification. This directly supports the security goal of integrity, which ensures data has not been altered in an unauthorized manner. Authentication, confidentiality, and availability are not the primary goals addressed by this mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication
Why it's wrong here
Authentication verifies an identity before granting access; it does not detect post-hoc modification of files. Hashing stored values and recomparing them addresses integrity, the goal of detecting unauthorised changes. Authentication would be the correct answer if the scenario concerned validating credentials or identities.
- ✓
Integrity
Why this is correct
Hashing detects unauthorised file modification because any change to the file's contents produces a different hash value, so comparison against the stored baseline reveals tampering. This directly satisfies the stem's requirement to detect unauthorised changes to critical files, supporting integrity rather than confidentiality or availability.
- ✗
Confidentiality
Why it's wrong here
Confidentiality prevents unauthorised disclosure, typically through encryption or access controls; a hash does not conceal file contents. Recomputing and comparing hashes reveals unauthorised modification, which is integrity. Confidentiality would be the correct goal if the scenario involved encrypting files or restricting who can read them.
- ✗
Availability
Why it's wrong here
Availability ensures systems and data remain accessible to authorised users; hashing files neither prevents outages nor maintains uptime. The scenario's comparison of stored and recalculated hashes detects tampering, which is integrity. Availability would be correct if the question concerned redundancy, failover or denial-of-service resilience.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.