Courseiva

CC · domain

Security Principles

Practise ISC2 Certified in Cybersecurity CC Security Principles practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

128 questions30 easy60 medium38 hard

Focused practice

Practice Security Principles questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Principles

Security Principles questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Principles exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Principles questions (128)

Click any question to see the full explanation, or start a practice session above.

1

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

Easy
2

A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)

Medium
3

An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?

Medium
4

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

Medium
5

What is the primary purpose of a digital signature?

Medium
6

A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:

Medium
7

Which of the following best describes a vulnerability in the context of risk management?

Medium
8

Which security principle ensures that data cannot be accessed by unauthorized individuals?

Easy
9

Which authentication type is a smart card an example of?

Easy
10

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

Easy
11

Which TWO of the following are examples of integrity controls? (Select TWO)

Easy
12

A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:

Medium
13

An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:

Hard
14

A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?

Medium
15

An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?

Hard
16

A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)

Hard
17

An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?

Easy
18

An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:

Hard
19

A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?

Medium
20

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Medium
21

A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?

Medium
22

An employee uses a password and a one-time code from a mobile authenticator app to log in. Which authentication type is being used?

Medium
23

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Hard
24

Which of the following is an example of a Type 2 authentication factor?

Medium
25

What is the primary purpose of a digital signature?

Hard
26

Which of the following is an example of a vulnerability?

Medium
27

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

Medium
28

A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?

Hard
29

Which TWO of the following are examples of Type 3 (inherence) authentication factors?

Easy
30

After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?

Hard
31

An organization requires employees to enter a password and then approve a push notification on their mobile device to access the corporate network. What type of authentication is this?

Medium
32

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

Medium
33

Which data classification level typically requires the highest level of protection?

Easy
34

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

Hard
35

After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:

Hard
36

A company conducts a background check on a new vendor before signing a contract. This activity is an example of:

Hard
37

A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?

Medium
38

Which type of authentication factor involves something the user knows?

Easy
39

A company performs background checks on potential employees before hiring. This action demonstrates which concept?

Medium
40

Which THREE of the following are considered risk management strategies? (Select THREE)

Hard
41

Which TWO of the following are examples of sensitive PII? (Select TWO.)

Medium
42

When implementing multi-factor authentication, which combination of factors is considered strongest?

Medium
43

What is the difference between due care and due diligence in security governance?

Medium
44

A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?

Hard
45

Which THREE of the following are examples of risk mitigation? (Select THREE)

Hard
46

An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?

Medium
47

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

Medium
48

Which of the following is an example of Type 2 authentication?

Easy
49

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Hard
50

A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?

Medium
51

A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:

Hard
52

An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:

Hard
53

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Medium
54

A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:

Medium
55

A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?

Easy
56

An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?

Medium
57

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Medium
58

A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?

Easy
59

A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:

Hard
60

An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)

Easy
61

An organization is developing a data classification policy. Which THREE of the following are common classification levels?

Hard
62

A system administrator implements version control for all configuration files. Which principle is being strengthened?

Medium
63

An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?

Easy
64

A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?

Medium
65

During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:

Hard
66

A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?

Medium
67

A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?

Hard
68

An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?

Hard
69

Which of the following ensures that data has not been tampered with during transmission?

Easy
70

According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?

Medium
71

Which of the following is considered Sensitive PII?

Easy
72

A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?

Medium
73

Which of the following is an example of a physical control that supports the availability principle of the CIA triad?

Easy
74

An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?

Hard
75

A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:

Hard
76

A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?

Hard
77

In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?

Hard
78

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

Medium
79

According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?

Hard
80

According to the (ISC)² Code of Ethics, which obligation has the highest priority?

Medium
81

Which of the following is a control that can reduce the risk of a DDoS attack?

Easy
82

A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).

Medium
83

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

Hard
84

An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?

Easy
85

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

Easy
86

Which of the following controls is primarily designed to ensure availability?

Medium
87

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

Hard
88

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

Medium
89

Which of the following is classified as sensitive PII?

Medium
90

Which of the following best describes the difference between due care and due diligence in security governance?

Hard
91

Which of the following is an example of a Type 2 authentication factor?

Easy
92

Which of the following is an example of a Type 1 authentication factor?

Medium
93

A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?

Medium
94

An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:

Medium
95

An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)

Medium
96

A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?

Medium
97

An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
98

An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:

Hard
99

According to the (ISC)² Code of Ethics, which principle has the highest priority?

Medium
100

An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?

Medium
101

What is the primary purpose of hashing in information security?

Easy
102

A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:

Hard
103

A company is classifying data and wants to ensure that personally identifiable information (PII) receives appropriate protection. Which two of the following are considered PII? (Choose two.)

Medium
104

Which of the following is an example of a Type 2 authentication factor?

Easy
105

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

Medium
106

A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)

Hard
107

Which of the following is considered sensitive personally identifiable information (PII)?

Medium
108

Which of the following best describes the purpose of due care in information security?

Easy
109

A security analyst is reviewing data handling procedures. Which THREE of the following are considered sensitive PII?

Hard
110

A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?

Hard
111

A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)

Medium
112

According to the (ISC)² Code of Ethics, which of the following has the highest priority?

Hard
113

Which of the following is considered sensitive Personally Identifiable Information (PII)?

Easy
114

A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:

Medium
115

Which of the following best describes a vulnerability in the context of risk management?

Medium
116

A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?

Medium
117

A financial institution is implementing data classification to protect customer information. They have identified data that includes medical records and financial account numbers. Which three labels are most appropriate for this data? (Choose three.)

Hard
118

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

Medium
119

A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:

Medium
120

A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:

Medium
121

Which of the following is an example of Type 2 (possession) authentication?

Easy
122

What is the primary goal of data classification?

Easy
123

Which of the following are examples of sensitive PII? (Select all that apply.)

Medium
124

Which of the following is an example of a Type 2 authentication factor?

Medium
125

Which of the following best describes the principle of confidentiality in the CIA triad?

Easy
126

An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
127

After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?

Hard
128

An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?

Medium

Frequently asked questions

What does the Security Principles domain cover on the CC exam?
Security Principles questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 128 Security Principles questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Principles questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cc ISC2-CC cc security principles Practice Questions