ISC2 CC Security Principles Practice Question
A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?
⚠ Common exam trap
The trap is that encryption is often assumed to cover integrity, but the exam expects candidates to distinguish confidentiality (encryption) from integrity (hashing and digital signatures) — picking encryption here is the classic CIA-triple confusion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Digital signatures
Digital signatures (C) are correct because they provide integrity and authenticity by allowing the recipient to verify that the data has not been altered and that it originated from a trusted source, using asymmetric cryptography to sign and verify a hash of the data. Hashing (D) is correct because it produces a fixed-length digest of the database contents, so any modification to the data changes the hash value, enabling detection of unauthorized or accidental changes and thereby protecting integrity. Encryption (B) primarily provides confidentiality, not integrity, since ciphertext can still be modified without detection unless combined with a MAC or signature. Load balancing (A) and redundant servers (E) improve availability and performance through distribution and failover, but they do not detect or prevent unauthorized data modification, so they do not directly protect integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Load balancing
Why it's wrong here
Load balancing distributes traffic to maintain performance and availability, not integrity; it neither detects nor prevents unauthorised modification of database contents. It is tempting because load balancing is common in database architectures, and it would be correct when the requirement is scalability or availability rather than data correctness.
- ✗
Encryption
Why it's wrong here
Encryption provides confidentiality by rendering data unreadable without the key; it does not detect or prevent unauthorised modification, which integrity requires. It is tempting because encryption is a core database control, and it would be correct when the requirement is protecting confidentiality of data at rest or in transit.
- ✓
Digital signatures
Why this is correct
Digital signatures verify that database records or transactions have not been altered after signing, directly satisfying the integrity requirement. Any modification invalidates the signature, providing cryptographic tamper detection rather than mere access control. This mechanism detects unauthorised changes, unlike confidentiality or availability controls.
- ✓
Hashing
Why this is correct
Hashing computes a fixed-length digest over database contents; any alteration to stored records produces a different digest, so comparison against a trusted baseline detects unauthorised modification. This directly satisfies the integrity objective by making tampering evident rather than preventing it.
- ✗
Redundant servers
Why it's wrong here
Redundant servers provide availability through failover, not integrity; they do not detect or prevent unauthorised data modification. It is tempting because redundancy is a standard database resilience control, and it would be correct when the requirement is ensuring continued access rather than protecting data correctness.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.