Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

An organization's data center experiences a power outage. The uninterruptible power supply (UPS) maintains power long enough for the backup generator to start, but the generator fails to start due to a fuel line blockage. The servers shut down, and critical data is lost. Which security principle was MOST directly compromised?

⚠ Common exam trap

The trap here is assuming that data loss always equates to an integrity breach, when in fact a loss of access due to power failure is primarily an availability issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Availability

The power outage and subsequent generator failure led to servers shutting down and data becoming inaccessible. Availability ensures that systems and data are accessible to authorized users when needed. The failure of backup power directly compromised availability, as the organization could not access its critical data. Confidentiality and integrity are not primarily affected because there is no unauthorized disclosure or modification, and non-repudiation is irrelevant to this physical infrastructure failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Confidentiality

    Why it's wrong here

    Confidentiality ensures that data is not disclosed to unauthorized individuals. In this scenario, there is no indication that data was accessed or disclosed improperly; the issue is that the data became unavailable due to a power failure. Confidentiality is not the primary concern here, as the integrity and availability of data are affected, but confidentiality remains intact.

  • ✓

    Availability

    Why this is correct

    Availability ensures that systems and data are accessible to authorized users when needed. Here, the power failure caused servers to shut down and data to become unavailable, directly violating availability. The UPS and generator were intended to maintain availability, but their failure resulted in a loss of access to critical data, making this the most directly compromised principle.

  • ✗

    Integrity

    Why it's wrong here

    Integrity ensures that data is not altered or destroyed in an unauthorized manner. While data loss occurred, it was due to a system shutdown, not an unauthorized modification. The primary failure is that the data was not accessible, which is an availability issue. Integrity could be a secondary concern if data was corrupted, but the scenario focuses on the loss of access, not alteration.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation ensures that a party cannot deny the authenticity of their signature or a message they sent. This scenario involves a power failure and data loss, not a dispute over the origin of a transaction or communication. Non-repudiation is unrelated to the physical infrastructure failure described, so it is not the compromised principle.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.