Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?

⚠ Common exam trap

CC often tests whether candidates can distinguish confidentiality (secrecy/reading) from integrity (modification) and non-repudiation (proof of origin) — eavesdropping is always a confidentiality violation, not integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confidentiality

Confidentiality ensures that data is only readable by authorized parties. When an attacker captures unencrypted email traffic in Wireshark and reads the contents, the confidentiality of the email is directly compromised because the data was exposed in plaintext to an unauthorized party.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Integrity

    Why it's wrong here

    Integrity concerns unauthorised modification of data, whereas the attacker only read unencrypted emails in transit; nothing was altered. Integrity controls such as hashing or checksums would be the focus if tampering, not eavesdropping, had occurred.

  • ✗

    Availability

    Why it's wrong here

    Availability concerns ensuring systems and data remain accessible to authorised users; the attacker's passive capture did not disrupt or deny access. Availability would be the goal at stake in a denial-of-service attack, not silent interception of unencrypted email.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation proves a party performed an action, typically via digital signatures or audit trails; reading traffic neither forges nor denies a sender's action. It would be the compromised goal if an attacker impersonated a sender or a party denied sending a message.

  • ✓

    Confidentiality

    Why this is correct

    Unencrypted email content is readable by anyone capturing the traffic, so unauthorised parties gain access to information they should not see. Confidentiality is the goal protecting data from disclosure, making it the property directly breached; integrity and availability remain intact.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.