ISC2 CC Security Principles Practice Question
An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?
⚠ Common exam trap
Test-takers frequently confuse encryption (confidentiality) with digital signatures (integrity/non-repudiation) — candidates often pick encryption because it sounds like it 'protects' the message, but it does not detect alteration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Digital signature
A digital signature uses the sender's private key to cryptographically sign the message hash, allowing the recipient to verify both the origin and that the message was not altered in transit. Any modification to the message invalidates the signature because the recomputed hash will not match. This provides integrity and non-repudiation, which is exactly what the organization needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access control
Why it's wrong here
Access control governs who may read or use a resource; it cannot detect whether an email's contents changed in transit. It would be correct when the requirement is restricting who can reach a system or data. Integrity of a transmitted message requires a hash or digital signature instead.
- ✓
Digital signature
Why this is correct
A digital signature is generated from a hash of the message encrypted with the sender's private key, so the recipient can verify integrity and confirm the content was not altered in transit, satisfying the tamper-detection requirement.
- ✗
Encryption
Why it's wrong here
Encryption provides confidentiality by making content unreadable to eavesdroppers, but it does not by itself prove a message was unaltered; some modes allow undetected modification. Hashing or a digital signature is needed for integrity. Encryption would be correct when the requirement is preventing unauthorised disclosure of data.
- ✗
Load balancing
Why it's wrong here
Load balancing distributes traffic across servers to maintain availability and performance; it has no mechanism for detecting modification of message content. It would be the correct choice when the requirement is resilience or scalability of a service, not integrity verification of transmitted email.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Non-repudiation
Non-repudiation is a security principle that ensures a party in a digital transaction cannot deny their involvement or the authenticity of their digital signature.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.