Courseiva
Security Principles →mediumMultiple Select

ISC2 CC Security Principles Practice Question

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

⚠ Common exam trap

The trap is that encryption is often assumed to cover integrity, but the exam expects candidates to distinguish confidentiality (encryption) from integrity (hashing and digital signatures) — picking encryption here is the classic CIA-triple confusion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Digital signatures

Digital signatures (C) are correct because they provide integrity and authenticity by allowing the recipient to verify that the data has not been altered and that it originated from a trusted source, using asymmetric cryptography to sign and verify a hash of the data. Hashing (D) is correct because it produces a fixed-length digest of the database contents, so any modification to the data changes the hash value, enabling detection of unauthorized or accidental changes and thereby protecting integrity. Encryption (B) primarily provides confidentiality, not integrity, since ciphertext can still be modified without detection unless combined with a MAC or signature. Load balancing (A) and redundant servers (E) improve availability and performance through distribution and failover, but they do not detect or prevent unauthorized data modification, so they do not directly protect integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Load balancing

    Why it's wrong here

    Load balancing distributes traffic to maintain performance and availability, not integrity; it neither detects nor prevents unauthorised modification of database contents. It is tempting because load balancing is common in database architectures, and it would be correct when the requirement is scalability or availability rather than data correctness.

  • ✗

    Encryption

    Why it's wrong here

    Encryption provides confidentiality by rendering data unreadable without the key; it does not detect or prevent unauthorised modification, which integrity requires. It is tempting because encryption is a core database control, and it would be correct when the requirement is protecting confidentiality of data at rest or in transit.

  • ✓

    Digital signatures

    Why this is correct

    Digital signatures verify that database records or transactions have not been altered after signing, directly satisfying the integrity requirement. Any modification invalidates the signature, providing cryptographic tamper detection rather than mere access control. This mechanism detects unauthorised changes, unlike confidentiality or availability controls.

  • ✓

    Hashing

    Why this is correct

    Hashing computes a fixed-length digest over database contents; any alteration to stored records produces a different digest, so comparison against a trusted baseline detects unauthorised modification. This directly satisfies the integrity objective by making tampering evident rather than preventing it.

  • ✗

    Redundant servers

    Why it's wrong here

    Redundant servers provide availability through failover, not integrity; they do not detect or prevent unauthorised data modification. It is tempting because redundancy is a standard database resilience control, and it would be correct when the requirement is ensuring continued access rather than protecting data correctness.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.