mediumMultiple Select
CIA Triad: Core Principles of Information Security
Which of the following are core principles of information security?
Quick Answer
The correct answer is Confidentiality, along with Integrity, as two of the three core principles of information security. These three principles form the CIA triad—Confidentiality, Integrity, and Availability—which is the foundational model for all security controls. Confidentiality ensures that sensitive data is accessible only to authorized users, typically enforced through encryption like AES-256, while Integrity guarantees that data has not been altered or tampered with, often verified using hashing algorithms such as SHA-256 or HMAC. On the ISC2 Certified in Cybersecurity CC exam, you will be tested on recognizing these three as the core principles, not supporting mechanisms like authentication or non-repudiation. A common trap is confusing confidentiality with privacy or integrity with availability, so remember that the triad is always these three together. To lock it in, use the mnemonic “CIA” itself—think of the agency that protects secrets (Confidentiality), ensures reports are accurate (Integrity), and keeps operations running (Availability).
⚠ Common exam trap
ISC2 often tests whether candidates can distinguish between core principles (CIA triad) and supporting security services (authentication, non-repudiation), leading many to incorrectly select authentication or non-repudiation as core principles instead of availability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrity
The CIA triad is the foundational model of information security, and its three core principles are Confidentiality, Integrity, and Availability. Option C (Confidentiality) is correct because it ensures data is disclosed only to authorized parties, typically enforced through encryption, access controls, and classification. Option B (Integrity) is correct because it guarantees data remains accurate, complete, and unaltered, protected via hashing, checksums, and digital signatures. Option E (Availability) is correct because it ensures systems and data are accessible to authorized users when needed, supported by redundancy, backups, and DDoS mitigation. Options A (Authentication) and D (Non-repudiation) are not core principles of the CIA triad; authentication is an access-control mechanism that verifies identity, and non-repudiation is a security service that prevents denial of an action, often achieved with digital signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication
Why it's wrong here
Authentication verifies an identity's claimed credentials; it is a supporting control, not one of the CIA triad principles. It would be the correct answer if the question asked about access control mechanisms rather than core security principles.
- ✓
Integrity
Why this is correct
Integrity ensures data remains accurate and unaltered unless changed by authorised processes, directly satisfying the core principles of information security alongside confidentiality and availability. It guards against unauthorised modification, whether accidental or malicious, making it a foundational pillar of the CIA triad that the question asks you to identify.
- ✓
Confidentiality
Why this is correct
Confidentiality is a core principle of information security, ensuring data is disclosed only to authorised parties. It forms one pillar of the CIA triad alongside integrity and availability, directly answering which principles underpin information security.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation guarantees that a party cannot deny performing an action, typically enforced through digital signatures and audit trails. It is a security service or property, not one of the CIA triad's core principles (confidentiality, integrity, availability). It would be the correct answer when a scenario requires proving the origin or delivery of a message, such as signed transactions.
- ✓
Availability
Why this is correct
Availability is a core principle of information security, ensuring systems and data remain accessible to authorised users when required. It completes the CIA triad with confidentiality and integrity, directly answering which principles underpin information security.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Confidentiality Integrity and Availability
The CIA Triad is a foundational security model that ensures data is kept secret, unaltered, and accessible when needed.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are core principles of the CIA triad?
medium- ✓ A.Confidentiality
- ✓ B.Integrity
- C.Non-repudiation
- D.Accountability
- ✓ E.Availability
Why A: Confidentiality (A) is a core CIA principle because it ensures information is not disclosed to unauthorized individuals, typically enforced through encryption, access controls, and classification. Integrity (B) is a core CIA principle because it guarantees data remains accurate, complete, and unaltered unless modified by authorized parties, using mechanisms like hashing, checksums, and digital signatures. Availability (E) is a core CIA principle because it ensures systems and data are accessible to authorized users when needed, supported by redundancy, backups, and DDoS mitigation. Non-repudiation (C) and accountability (D) are important security concepts but are not part of the CIA triad; non-repudiation is often grouped with authentication and integrity services, while accountability relates to auditing and traceability rather than the three foundational CIA pillars.
Variation 2. Which TWO of the following are core principles of the CIA triad?
easy- ✓ A.Integrity
- B.Non-repudiation
- ✓ C.Confidentiality
- D.Authorization
- E.Authentication
Why A: The CIA triad consists of Confidentiality, Integrity, and Availability. Options A and C are correct. Option B (Non-repudiation) is separate. Option D (Authentication) is separate. Option E (Authorization) is separate.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.