Courseiva
hardMultiple Choice

ISC2 CC Practice Question: After a security breach, investigators find that…

After a security breach, investigators find that an attacker exploited a vulnerability in a publicly accessible application to gain access to internal databases. Which security principle would have most effectively limited the impact?

⚠ Common exam trap

Candidates often choose confidentiality or accountability because they sound relevant, but the question asks for the principle that would have most effectively limited the impact of a breach, which is defense in depth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense in depth

Defense in depth is the principle of layering multiple security controls so that if one fails, others still protect the assets. In this scenario, a publicly accessible application was exploited to reach internal databases; defense in depth would have included network segmentation, least privilege, and additional controls that could have prevented or limited the attacker's lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accountability

    Why it's wrong here

    Accountability traces actions to an identity after the fact, but does not prevent a compromised public application from pivoting to internal databases; only segmentation or least privilege limits that impact. It is tempting because logging and attribution matter in investigations, and would be correct where the requirement is to hold users answerable for their actions.

  • ✗

    Confidentiality

    Why it's wrong here

    Confidentiality protects data from unauthorised disclosure through encryption and access controls; it does not constrain how far an attacker can move after compromising an application. Least privilege would have limited the breach's reach by denying the application broad database rights. Confidentiality is the goal when protecting data at rest or in transit.

  • ✓

    Defense in depth

    Why this is correct

    Defense in depth layers controls — network segmentation, least privilege, monitoring — so breaching the public application does not grant direct database access. The stem's impact limitation is satisfied because no single exploited vulnerability yields full internal reach.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation proves a party performed an action, typically via digital signatures, so it cannot stop an exploited public application from reaching internal databases. It is tempting because it supports audit and dispute resolution, and would be the right principle when the requirement is to prevent someone denying having sent data or authorised a transaction.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.