Courseiva
Security Principles →mediumMultiple Select

ISC2 CC Security Principles Practice Question

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

⚠ Common exam trap

The CC exam often tests the Code of Ethics by presenting actions that sound efficient or loyal to the employer (sharing passwords, hiding breaches) — candidates who prioritize organizational loyalty over the Code's canons pick the wrong answers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reporting a discovered vulnerability to the software vendor promptly

Option C is correct because the (ISC)² Code of Ethics requires members to act honorably, honestly, justly, responsibly, and legally, and responsibly disclosing a discovered vulnerability to the software vendor reflects the canon to protect society and the infrastructure. Option D is correct because safeguarding confidential client information and refusing to release a password to an unauthorized third party upholds the canon to advance the profession and act responsibly toward clients and employers. Option A is wrong because using unlicensed software is illegal and unethical, violating the canon to act legally and avoid conflicts with laws. Option B is wrong because sharing a colleague's password without consent violates privacy, confidentiality, and the canon to act honorably and responsibly. Option E is wrong because concealing a breach is dishonest and harms stakeholders, contradicting the canons to act honestly and protect society.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using a vendor's software without a license to test its security

    Why it's wrong here

    Unlicensed use breaches the canon requiring professionals to act legally and avoid conflicts with laws and contracts. It is tempting because security testing is a legitimate defensive activity, and unlicensed software would be acceptable only when the vendor has granted explicit written permission or a trial licence.

  • ✗

    Sharing a colleague's password with a manager without the colleague's consent to improve efficiency

    Why it's wrong here

    Sharing credentials without consent violates the canon requiring professionals to protect confidential information and act honourably toward colleagues. It is tempting because managers often appear authorised to access team resources, and credential sharing would be defensible only under a documented, consented delegation procedure.

  • ✓

    Reporting a discovered vulnerability to the software vendor promptly

    Why this is correct

    Prompt disclosure to the vendor lets the flaw be fixed before attackers exploit it, upholding the canon to advance the profession and protect the public. This satisfies the stem's requirement for an action aligned with the (ISC)² Code's canons.

  • ✓

    Refusing to share a confidential client password with an unauthorized third party

    Why this is correct

    Refusing to share a confidential client password with an unauthorised third party upholds the canon to protect the profession and act honourably, lawfully and justly. It safeguards the client's confidential information, aligning with the Code's duty to avoid harming others.

  • ✗

    Concealing a security breach to avoid negative publicity

    Why it's wrong here

    Concealment breaches the canon requiring prompt disclosure of significant security matters to appropriate parties. It is tempting because reputational damage is a real business concern, and delaying disclosure would be defensible only where legal counsel directs a brief, documented hold for active investigation.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.