Which TWO of the following are principles of the CIA triad? (Select TWO.)
Confidentiality ensures information is disclosed only to authorised parties, preventing unauthorised reading or exposure. It forms one of the three core CIA triad principles, alongside integrity and availability, and is therefore a correct selection here.
Why this answer
Confidentiality (A) is a core principle of the CIA triad because it ensures that information is accessible only to authorized parties, typically enforced through encryption, access controls, and classification. Integrity (B) is also a core principle, guaranteeing that data remains accurate, complete, and unaltered except by authorized actions, supported by hashing, checksums, and version controls. Together with Availability, these three form the CIA triad, the foundational model for information security.
Non-repudiation (C) is a related security property ensuring a party cannot deny an action, but it is not one of the three CIA principles. Accountability (D) and Authorization (E) are important access-control and governance concepts, yet neither is a member of the CIA triad.
Exam trap
ISC2 often tests candidates by listing security concepts like non-repudiation or authorization as distractors, expecting you to know that the CIA triad strictly includes only confidentiality, integrity, and availability.