Courseiva

CC · domain

Security Principles

Security Principles is the largest CC domain, covering the CIA triad, governance, risk management, security controls, and privacy. Questions are scenario-based: you read a short situation and identify which principle, control type, or risk response is being applied, or which CIA element a given safeguard primarily protects.

168 questions38 easy79 medium51 hard

Focused practice

Practice Security Principles questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Principles

Given a scenario, classify the control by type and function and name the risk response or CIA element involved. The single most important skill is reading what the control actually does, not what it sounds like, before choosing an answer.

Applying confidentiality, integrity, and availability to specific safeguards like file integrity monitoring and encryption

Classifying controls as physical, administrative, or technical, and as preventive, detective, corrective, or compensating

Matching risk responses: risk avoidance, mitigation, transference, and acceptance, including documented risk acceptance

Distinguishing governance elements such as policies, standards, procedures, baselines, and the ISC2 Code of Ethics

Watch out for

Common Security Principles exam traps

  • ▸Treating any documented decision to live with a risk as mitigation; accepting an isolated, compensating-controlled legacy system is risk acceptance
  • ▸Labeling a control by its mechanism rather than its function; a control can be technical yet detective, or physical yet preventive
  • ▸Confusing integrity with confidentiality; version control and file integrity monitoring protect data integrity, not secrecy

Question index

All Security Principles questions (168)

Click any question to see the full explanation, or start a practice session above.

1

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

Easy
2

A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)

Medium
3

An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?

Medium
4

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

Medium
5

What is the primary purpose of a digital signature?

Medium
6

A hospital's IT department is designing a new electronic health record system. The security architect proposes that all patient records be encrypted both at rest and in transit, and that access be restricted based on job roles. Which security principle is the architect primarily addressing?

Medium
7

A healthcare organization wants to ensure that only authorized clinicians can view patient records, while also maintaining a detailed log of every access for compliance audits. Which security principle is primarily being addressed by restricting access and recording all access attempts?

Medium
8

A retail company's security policy states that no single employee should be able to both create a vendor payment and approve it. The company assigns these duties to two different people. Which security principle is the policy enforcing?

Medium
9

A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:

Medium
10

Which of the following best describes a vulnerability in the context of risk management?

Medium
11

Which security principle ensures that data cannot be accessed by unauthorized individuals?

Easy
12

Which authentication type is a smart card an example of?

Easy
13

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

Easy
14

Which TWO of the following are examples of integrity controls? (Select TWO)

Easy
15

A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:

Medium
16

An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:

Hard
17

A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?

Medium
18

An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?

Hard
19

A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)

Hard
20

A hospital's IT department is choosing a security control to protect patient records. The control must render data unreadable to anyone who does not hold the cryptographic key, even if the storage media is stolen. Which type of control BEST meets this requirement?

Easy
21

An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?

Easy
22

An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:

Hard
23

A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?

Medium
24

A security team decides to implement multi-factor authentication for all remote access. Which combination of factors would constitute multi-factor authentication?

Medium
25

A security manager is developing a disaster recovery plan for a critical database. The manager needs to determine the maximum tolerable downtime (MTD) for the database. Which of the following should the manager consider FIRST when establishing the MTD?

Medium
26

A software development company wants to ensure that only authorized code changes are deployed to production. They implement a process where developers submit code changes, and a separate team reviews and approves them before deployment. Which security principle is BEST demonstrated by this process?

Hard
27

A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?

Medium
28

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Hard
29

Which of the following is an example of a vulnerability?

Medium
30

A security manager is mapping several controls to the categories of administrative, technical, and physical. Which TWO of the following are administrative controls? (Choose two.)

Hard
31

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

Medium
32

A security analyst is assessing the risk associated with a new web application. The analyst identifies that the application has a SQL injection vulnerability, and there is a known exploit available that could allow an attacker to extract sensitive data. The application is exposed to the internet and is used by customers. Which two factors are most directly involved in determining the level of risk? (Choose two.)

Hard
33

A retail company wants to reduce the risk of fraudulent online purchases. The security manager proposes requiring customers to enter a password plus a code sent to their registered mobile phone. Which security concept does this proposal best illustrate?

Medium
34

A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?

Hard
35

Which TWO of the following are examples of Type 3 (inherence) authentication factors?

Easy
36

After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?

Hard
37

A hospital's IT department wants to ensure that only authorized clinicians can view patient records, while also guaranteeing that those records have not been tampered with. Which security principle is primarily concerned with preventing unauthorized disclosure of the records?

Easy
38

An e-commerce company notices that its product reviews are being scraped by automated bots far more aggressively than expected, and the resulting traffic is degrading checkout performance for real customers. The security team wants a control that slows automated abuse without challenging legitimate buyers. Which security principle does this control primarily support?

Medium
39

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

Medium
40

A retail chain wants to reduce the chance that a former employee can still access the point-of-sale system weeks after leaving the company. The security manager proposes a control that automatically disables accounts on the employee's last working day. Which type of control is this?

Easy
41

Which data classification level typically requires the highest level of protection?

Easy
42

A financial services firm is classifying a risk by estimating how often a particular attack is likely to succeed in a given year. Which risk concept is the firm measuring?

Medium
43

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

Hard
44

A mid-sized accounting firm is drafting its first information security policy. The partners want the policy to address governance responsibilities clearly so that security decisions are made consistently at the right levels. Which TWO of the following are governance responsibilities that the policy should assign? (Choose two.)

Medium
45

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor plans to publish a hash of the patch file on its website alongside the download. A security consultant warns that this approach alone is insufficient. Why is publishing only a hash inadequate for this goal?

Hard
46

After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:

Hard
47

A hospital wants to ensure that patient records can only be viewed by authorized clinical staff, and that any modification to a record is traceable to the individual who made it. Which security principle directly supports both of these requirements?

Easy
48

A company conducts a background check on a new vendor before signing a contract. This activity is an example of:

Hard
49

A security analyst is reviewing access control models. Which two of the following are characteristics of the principle of least privilege? (Choose two.)

Hard
50

A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?

Medium
51

Which type of authentication factor involves something the user knows?

Easy
52

A security administrator is reviewing the organization's authentication controls and wants to strengthen them by adding factors from different categories. Which TWO of the following represent distinct authentication factor categories that can be combined to achieve multi-factor authentication? (Choose two.)

Medium
53

A company performs background checks on potential employees before hiring. This action demonstrates which concept?

Medium
54

Which THREE of the following are considered risk management strategies? (Select THREE)

Hard
55

Which TWO of the following are examples of sensitive PII? (Select TWO.)

Medium
56

An online retailer stores customer credit card numbers. Management decides to retain only the last four digits and delete the full numbers after payment authorization. Which security principle does this decision best illustrate?

Hard
57

When implementing multi-factor authentication, which combination of factors is considered strongest?

Medium
58

An organization is reviewing its security governance framework. Which TWO of the following are primary objectives of security governance? (Choose two.)

Medium
59

A small clinic stores patient records on a server. The IT administrator ensures that only authorized staff can view these records, and that the records remain accurate and available when needed. Which security principle is best illustrated by restricting access to the records?

Easy
60

What is the difference between due care and due diligence in security governance?

Medium
61

A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?

Hard
62

A security manager is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The manager needs to identify which of the following are considered threats rather than vulnerabilities or risks. (Choose two.)

Medium
63

Which THREE of the following are examples of risk mitigation? (Select THREE)

Hard
64

An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?

Medium
65

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

Medium
66

Which of the following is an example of Type 2 authentication?

Easy
67

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Hard
68

A security analyst is evaluating the risk of a ransomware attack on a company's file server. The analyst determines that the likelihood of an attack is high and the potential impact is severe. However, the company has a reliable offline backup that can restore all data within four hours. How should the analyst classify the risk?

Hard
69

A company stores backup tapes containing customer data in an offsite vault. The security policy requires that if the tapes are lost or stolen, the data cannot be read by unauthorized parties. Which control should the company implement to meet this requirement?

Medium
70

A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?

Medium
71

A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:

Hard
72

An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:

Hard
73

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Medium
74

A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:

Medium
75

A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?

Easy
76

An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?

Medium
77

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Medium
78

A software development company wants to ensure that only authorized code changes are deployed to production. The security team proposes that developers should not have direct write access to the production environment, and that all code must be reviewed and approved by a different team member before deployment. Which security principle does this proposal primarily enforce?

Hard
79

A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?

Easy
80

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor signs the patch with its private key. Which security property does this provide to customers who verify the signature with the vendor's public key?

Hard
81

A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:

Hard
82

A company experiences a ransomware attack that encrypts its file servers. The security team restores operations from offline backups taken the previous night. Which security principle does the restoration from backups primarily support?

Medium
83

An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)

Easy
84

A financial services company wants to ensure that a terminated employee cannot continue to use an active badge to enter the building after their last day. The security manager reviews physical access control procedures. Which control type is being applied when the badge is deactivated in the access control system?

Medium
85

A security officer at a healthcare provider is reviewing the organization's risk management program. The officer must distinguish between threats and vulnerabilities when documenting risks. Which two of the following are examples of vulnerabilities rather than threats? (Choose two.)

Hard
86

A system administrator implements version control for all configuration files. Which principle is being strengthened?

Medium
87

An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?

Easy
88

A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?

Medium
89

During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:

Hard
90

Maya is a security administrator at a healthcare company. She discovers that nurses can view patient billing records even though their job duties only require access to clinical treatment notes. She wants to apply the security principle that restricts users to only the data they need to perform their assigned tasks. Which principle should she implement?

Easy
91

A payroll administrator can view salary records for all employees during normal business hours, but only after her manager approves each access request and the system logs the action. Which security principle is BEST illustrated by limiting her access to what her job requires and only when needed?

Medium
92

A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?

Medium
93

A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?

Hard
94

An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?

Hard
95

Which of the following ensures that data has not been tampered with during transmission?

Easy
96

According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?

Medium
97

A healthcare provider must ensure that patient records remain unaltered during storage and transmission between clinics. Which security principle is being addressed when the organization implements hashing and digital signatures on those records?

Easy
98

Which of the following is considered Sensitive PII?

Easy
99

A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?

Medium
100

Which of the following is an example of a physical control that supports the availability principle of the CIA triad?

Easy
101

A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)

Medium
102

An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?

Hard
103

An organization's data center experiences a power outage. The uninterruptible power supply (UPS) maintains power long enough for the backup generator to start, but the generator fails to start due to a fuel line blockage. The servers shut down, and critical data is lost. Which security principle was MOST directly compromised?

Easy
104

A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:

Hard
105

A security analyst is investigating a potential breach. The analyst discovers that an attacker gained access to a server by exploiting a known vulnerability that was not patched. The attacker then installed malware that encrypted critical files and demanded payment. Which of the following best describes the role of the unpatched vulnerability in this incident?

Hard
106

A junior analyst reports that an attacker exploited an unpatched web server to steal customer data. The analyst labels the missing patch the 'risk'. According to standard risk terminology, how should the missing patch be classified?

Hard
107

A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?

Hard
108

In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?

Hard
109

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

Medium
110

A security manager is documenting how the organization decides which safeguards to apply to a new customer database. The team identifies the value of the data, the threats that could exploit weaknesses, and the potential business impact, then selects controls that reduce risk to an acceptable level. Which concept best describes this activity?

Hard
111

According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?

Hard
112

According to the (ISC)² Code of Ethics, which obligation has the highest priority?

Medium
113

Which of the following is a control that can reduce the risk of a DDoS attack?

Easy
114

A company's security policy states that employees must wear identification badges visibly at all times while on premises. A security guard checks badges at the entrance. Which type of control is the badge check?

Medium
115

A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).

Medium
116

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

Hard
117

An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?

Easy
118

A security manager is reviewing the organization's approach to risk. The manager decides to purchase cyber insurance to transfer some of the financial risk associated with a data breach. Which risk management strategy is being used?

Hard
119

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

Easy
120

An organization implements a defense-in-depth strategy by deploying firewalls, intrusion detection systems, and endpoint protection. Which security principle does this approach primarily demonstrate?

Medium
121

A hospital's compliance officer is mapping controls for a new patient portal. The legal team wants documented assurance that a clinician cannot later deny having approved a medication order submitted through the portal. Which security principle is the legal team most directly requesting?

Hard
122

A software development company wants to prevent a dismissed contractor from using credentials that were issued during the contract period to access internal code repositories. Which administrative control should the company apply?

Medium
123

A software development team is designing a new application that will process credit card payments. The security architect recommends that the application should not store the card verification value (CVV) after the transaction is authorized. Which principle is the architect applying?

Medium
124

A financial services firm wants to ensure that a single employee cannot initiate and approve a large wire transfer alone. The firm implements a process where one employee creates the transfer and a different employee must approve it. Which security principle is being applied?

Medium
125

Which of the following controls is primarily designed to ensure availability?

Medium
126

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

Hard
127

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

Medium
128

Which of the following is classified as sensitive PII?

Medium
129

A junior security administrator at a hospital is told that only nurses and physicians on the current shift should be able to view patient records, and that records must be protected from disclosure to anyone else. Which security principle is this requirement primarily enforcing?

Easy
130

A financial institution wants to implement a control that verifies the identity of a user by requiring something the user knows and something the user has. Which of the following authentication mechanisms best meets this requirement?

Medium
131

Which of the following best describes the difference between due care and due diligence in security governance?

Hard
132

Which of the following is an example of a Type 2 authentication factor?

Easy
133

A company's security policy states that only staff in the finance department may access the general ledger, and that access must be reviewed every quarter. An auditor finds that two former finance employees still hold active accounts with ledger permissions. Which concept has the organization FAILED to apply?

Medium
134

Which of the following is an example of a Type 1 authentication factor?

Medium
135

A security manager is assessing the risk of a new web application. The manager identifies that the application has a known SQL injection vulnerability, and that attackers frequently scan for such flaws. Which term best describes the SQL injection flaw itself?

Hard
136

A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?

Medium
137

An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:

Medium
138

An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)

Medium
139

A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?

Medium
140

An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
141

An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:

Hard
142

According to the (ISC)² Code of Ethics, which principle has the highest priority?

Medium
143

An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?

Medium
144

What is the primary purpose of hashing in information security?

Easy
145

A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:

Hard
146

A security manager is reviewing the organization's risk management approach. She wants to ensure that the team correctly distinguishes between threats, vulnerabilities, and risks. Which two of the following statements correctly describe these concepts? (Choose two.)

Hard
147

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

Medium
148

A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)

Hard
149

Which of the following is considered sensitive personally identifiable information (PII)?

Medium
150

Which of the following best describes the purpose of due care in information security?

Easy
151

A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?

Hard
152

An organization wants to implement multi-factor authentication (MFA) for remote access by requiring a password and a smart card. Which two authentication factors are used in this MFA implementation? (Choose two.)

Easy
153

A financial institution wants to ensure that a wire transfer request cannot be denied by the sender later. The security team implements a mechanism where the sender's private key is used to sign the transaction. Which security principle does this primarily support?

Medium
154

A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)

Medium
155

According to the (ISC)² Code of Ethics, which of the following has the highest priority?

Hard
156

A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:

Medium
157

A security manager is training new employees on the concept of risk. She explains that risk is composed of several elements. Which TWO of the following are components that directly contribute to risk? (Choose two.)

Medium
158

A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?

Medium
159

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

Medium
160

A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:

Medium
161

A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:

Medium
162

What is the primary goal of data classification?

Easy
163

Which of the following are examples of sensitive PII? (Select all that apply.)

Medium
164

Which of the following best describes the principle of confidentiality in the CIA triad?

Easy
165

An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
166

After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?

Hard
167

A hospital's compliance officer must decide how to protect patient records. The records must remain readable only to authorized clinicians while in storage and in transit. Which security principle is the compliance officer primarily applying?

Easy
168

An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?

Medium

Frequently asked questions

What does the Security Principles domain cover on the CC exam?
Given a scenario, classify the control by type and function and name the risk response or CIA element involved. The single most important skill is reading what the control actually does, not what it sounds like, before choosing an answer.
How many questions are in this domain?
This page lists all 168 Security Principles questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Principles questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cc ISC2-CC cc security principles Practice Questions