Courseiva
easyMultiple Choice

ISC2 CC Practice Question: A security administrator notices that a user's…

A security administrator notices that a user's account has been used to access sensitive files at unusual hours. Which security principle would most effectively help detect this type of activity?

⚠ Common exam trap

Many exam-takers confuse accountability with non-repudiation, as both involve tracing actions, but non-repudiation is about proving an action occurred, while accountability is about detecting and logging who did what.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accountability

Accountability is the security principle that ensures every action on a system can be traced back to a specific user or entity. It relies on mechanisms like audit logs, user authentication, and session tracking to record who did what and when. In this scenario, detecting unusual access times requires reviewing logs that link the access to the user's account, which is the essence of accountability. Without accountability, there would be no way to attribute the activity to the user or detect the anomaly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation proves a party performed an action after the fact, such as signing or sending, but does not flag unusual access in real time. It is tempting because logs and digital signatures support accountability, and would be correct if the question asked how to prevent a user denying they accessed the files.

  • ✗

    Availability

    Why it's wrong here

    Availability concerns uptime and access to systems and data, not identifying anomalous account usage. It is tempting because unusual-hours access could indicate an availability-impacting attack, and would be the correct principle when the scenario concerns resilience, redundancy or denial-of-service protection rather than detection.

  • ✗

    Integrity

    Why it's wrong here

    Integrity concerns unauthorised modification of data, so it detects tampering rather than anomalous access patterns. It is tempting because sensitive files are involved and hashing or checksums could reveal alteration, and would be the correct principle if the scenario described changed file contents rather than odd login times.

  • ✓

    Accountability

    Why this is correct

    Accountability ties every action to an authenticated identity through logging and audit trails, so out-of-hours access to sensitive files is attributable and detectable. This satisfies the stem's detection requirement, since accountability mechanisms record who did what and when, exposing anomalous usage that authentication alone would not reveal.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.