Courseiva

CCNA Security Principles Questions

18 of 168 questions · Page 3/3 · Security Principles · Answers revealed

151
MCQhard

A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?

A.Symmetric encryption
B.Digital signature
C.Access control list
D.Hashing
AnswerB

A digital signature uses asymmetric cryptography: the signer's private key creates a hash-based value that any verifier can check with the public key. Altering the document invalidates that value, directly satisfying the requirement to detect changes since signing.

Why this answer

A digital signature uses asymmetric cryptography to sign a document's hash with the signer's private key, allowing anyone with the public key to verify both the signer's identity and that the document has not been altered. This provides integrity and non-repudiation, directly satisfying the requirement.

Exam trap

The trap is confusing hashing with digital signatures — hashing detects alteration but does not prove who signed, so candidates who pick hashing miss the non-repudiation requirement.

How to eliminate wrong answers

Option A is wrong because symmetric encryption provides confidentiality, not integrity verification or proof of origin. Option C is wrong because an ACL controls access permissions to resources, not document integrity. Option D is wrong because hashing alone detects alteration but does not bind the hash to a signer, so it cannot prove who signed or prevent an attacker from replacing both the document and its hash.

152
Multi-Selecteasy

An organization wants to implement multi-factor authentication (MFA) for remote access by requiring a password and a smart card. Which two authentication factors are used in this MFA implementation? (Choose two.)

Select 2 answers
A.Password
B.Smart card
C.Retina scan
D.Fingerprint scan
E.OTP token
AnswersA, B

Password is a knowledge factor (Type 1). Combining it with a possession factor like a smart card meets the definition of MFA.

Why this answer

Multi-factor authentication requires at least two different types of factors. A password is Type 1 (knowledge) and a smart card is Type 2 (possession), so combining them qualifies as MFA.

153
MCQmedium

A financial institution wants to ensure that a wire transfer request cannot be denied by the sender later. The security team implements a mechanism where the sender's private key is used to sign the transaction. Which security principle does this primarily support?

A.Availability
B.Integrity
C.Non-repudiation
D.Confidentiality
AnswerC

Non-repudiation ensures that a party cannot deny the authenticity of their signature on a document or the sending of a message. By signing the wire transfer with a private key, the sender cannot later claim they did not authorize it. This directly supports non-repudiation, which is crucial for financial transactions to prevent fraud and disputes.

Why this answer

The correct answer is non-repudiation. Using a private key to sign a wire transfer provides proof of origin and prevents the sender from denying the transaction. While digital signatures also support integrity, the specific requirement to prevent denial makes non-repudiation the primary principle.

Confidentiality and availability are unrelated to this scenario's goal.

Exam trap

The trap here is assuming that digital signatures only provide integrity, overlooking that they also deliver non-repudiation, which is the key requirement in this scenario.

154
Multi-Selectmedium

A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)

Select 2 answers
A.A PIN
B.A hardware OTP token
C.A fingerprint
D.A password
E.A smart card
AnswersB, E

A hardware OTP token is a physical device issued to the user, so presenting its generated code demonstrates possession. That tangible-device characteristic is precisely what qualifies it as a Type 2 factor rather than knowledge or inherence.

Why this answer

A hardware OTP token (B) is correct because it is a physical device the user must possess, and it generates one-time passcodes, making it a classic Type 2 possession factor. A smart card (E) is also correct because it is a physical object the user holds and inserts or taps to authenticate, fitting the possession category. In contrast, a PIN (A) and a password (D) are knowledge factors (Type 1) because they rely on something the user knows, and a fingerprint (C) is an inherence factor (Type 3) because it relies on a biometric characteristic of the user.

Exam trap

CC often tests the confusion between knowledge and possession factors; candidates mistakenly classify a PIN or password as 'something you have' because it's stored on a device, or mislabel biometrics as possession.

155
MCQhard

According to the (ISC)² Code of Ethics, which of the following has the highest priority?

A.Provide diligent and competent service to principals
B.Act honorably, honestly, justly, responsibly, and legally
C.Protect society, the common good, necessary public trust and confidence, and the infrastructure
D.Advance and protect the profession
AnswerC

The Code of Ethics ranks obligations to the public above duties to clients and employers. Protecting society, the common good, public trust and the infrastructure is the paramount imperative, so it takes precedence over all other canons when interests conflict.

Why this answer

The (ISC)² Code of Ethics canons are ordered by priority, and the first canon is to protect society, the common good, necessary public trust and confidence, and the infrastructure. This takes precedence over duties to principals, the profession, and self. The other canons follow in descending order.

Exam trap

CC often tests the order of the (ISC)² canons; candidates frequently assume duty to the client (principal) is paramount, but the exam emphasizes society and public trust as the highest priority.

How to eliminate wrong answers

Option A is wrong because providing diligent and competent service to principals is the third canon, lower priority than protecting society. Option B is wrong because acting honorably, honestly, justly, responsibly, and legally is the second canon, not the highest. Option D is wrong because advancing and protecting the profession is the fourth and lowest-priority canon.

156
MCQmedium

A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:

A.Risk avoidance
B.Risk acceptance
C.Risk mitigation
D.Risk transfer
AnswerB

Risk acceptance means acknowledging a risk and choosing to bear its potential impact without further mitigation, which matches the decision to tolerate the unpatched legacy system because isolation and compensating controls reduce exposure to an acceptable level.

Why this answer

Risk acceptance means the organization acknowledges the risk and chooses to retain it without taking further action, often because the cost of mitigation outweighs the potential impact or because compensating controls reduce it to an acceptable level. Here, the legacy system is isolated with compensating controls, so the organization formally accepts the residual risk.

Exam trap

CC often tests the distinction between acceptance and mitigation; candidates see 'compensating controls' and pick mitigation, but the key phrase is 'decides to accept the risk' — the controls justify acceptance, not further action.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or system that introduces the risk entirely, not keeping it. Option C is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact, which the organization has already done via isolation and compensating controls; the decision to not do more is acceptance. Option D is wrong because risk transfer shifts the risk to a third party, such as through insurance or outsourcing, which is not described here.

157
Multi-Selectmedium

A security manager is training new employees on the concept of risk. She explains that risk is composed of several elements. Which TWO of the following are components that directly contribute to risk? (Choose two.)

Select 2 answers
A.Policy
B.Control
C.Threat
D.Vulnerability
E.Audit
AnswersC, D

A threat is any potential cause of an unwanted incident that could harm an asset. In risk management, threat is a core component because risk exists only when there is a threat that can exploit a vulnerability. Without a threat, a vulnerability alone does not create risk. Therefore, threat directly contributes to risk and is one of the correct elements.

Why this answer

Risk is commonly defined as the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact. Threat and vulnerability are the two essential components that must be present for risk to exist. Policy, audit, and control are important security concepts, but they are not direct constituents of risk; rather, they are mechanisms used to govern, verify, or mitigate risk.

Exam trap

The trap here is including controls or policies as components of risk, when actually they are responses to risk and not part of its fundamental definition.

158
MCQmedium

A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?

A.Authentication
B.Integrity
C.Availability
D.Confidentiality
AnswerC

Redundant servers with immediate failover keep services accessible when one server fails, directly addressing the availability principle. Availability ensures authorised users can access systems and data when required, which is precisely the uptime guarantee the redundant design delivers.

Why this answer

Redundant servers ensure that if one fails, another takes over immediately, maintaining uptime and continuous access to resources. This directly addresses the security principle of availability, which ensures systems and data are accessible when needed.

Exam trap

The trap is confusing availability with integrity or confidentiality; candidates may think redundancy protects data from tampering, but it primarily ensures uptime.

How to eliminate wrong answers

Option A is wrong because authentication verifies identity, which is not addressed by redundancy. Option B is wrong because integrity ensures data is not altered, which is unrelated to server failover. Option D is wrong because confidentiality ensures data is not disclosed to unauthorized parties, which is not the focus of redundancy.

159
Multi-Selectmedium

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

Select 2 answers
A.Using a vendor's software without a license to test its security
B.Sharing a colleague's password with a manager without the colleague's consent to improve efficiency
C.Reporting a discovered vulnerability to the software vendor promptly
D.Refusing to share a confidential client password with an unauthorized third party
E.Concealing a security breach to avoid negative publicity
AnswersC, D

Prompt disclosure to the vendor lets the flaw be fixed before attackers exploit it, upholding the canon to advance the profession and protect the public. This satisfies the stem's requirement for an action aligned with the (ISC)² Code's canons.

Why this answer

Option C is correct because the (ISC)² Code of Ethics requires members to act honorably, honestly, justly, responsibly, and legally, and responsibly disclosing a discovered vulnerability to the software vendor reflects the canon to protect society and the infrastructure. Option D is correct because safeguarding confidential client information and refusing to release a password to an unauthorized third party upholds the canon to advance the profession and act responsibly toward clients and employers. Option A is wrong because using unlicensed software is illegal and unethical, violating the canon to act legally and avoid conflicts with laws.

Option B is wrong because sharing a colleague's password without consent violates privacy, confidentiality, and the canon to act honorably and responsibly. Option E is wrong because concealing a breach is dishonest and harms stakeholders, contradicting the canons to act honestly and protect society.

Exam trap

The CC exam often tests the Code of Ethics by presenting actions that sound efficient or loyal to the employer (sharing passwords, hiding breaches) — candidates who prioritize organizational loyalty over the Code's canons pick the wrong answers.

160
MCQmedium

A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:

A.Risk transfer
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerC

Accepting the risk means the organisation acknowledges the vulnerability but chooses to tolerate it because remediation costs outweigh the potential financial loss. This deliberate decision to absorb the residual risk, rather than mitigate, transfer or avoid it, is the defining characteristic of risk acceptance within the risk management process.

Why this answer

Risk acceptance means acknowledging the risk and choosing not to mitigate it, often due to cost-benefit analysis.

161
MCQmedium

A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:

A.Due diligence
B.Risk transfer
C.Risk avoidance
D.Due care
AnswerA

Due diligence is the systematic investigation a company performs before engaging a provider, covering security controls, compliance certifications and risk posture. It directly satisfies the stem's requirement to thoroughly investigate the provider's practices and standards conformance, distinguishing it from ongoing monitoring or contractual assurance obtained after selection.

Why this answer

Due diligence involves investigating and assessing risks before making decisions, such as vendor selection.

162
MCQeasy

What is the primary goal of data classification?

A.To improve data access speed
B.To comply with marketing requirements
C.To determine the appropriate level of security controls
D.To reduce storage costs
AnswerC

Data classification assigns sensitivity labels that directly dictate which security controls apply, satisfying the stem's requirement for a primary goal. By categorising information according to its value and sensitivity, organisations can apply proportionate protection, ensuring Microsoft Entra ID access policies and encryption align with each data type's risk profile.

Why this answer

Data classification is the process of categorizing data based on its sensitivity, value, and regulatory requirements so that appropriate security controls (encryption, access control, retention, handling procedures) can be applied proportionally. Its primary purpose is to ensure that protection levels match the data's risk profile. This is the foundational step in any data governance or security program.

Exam trap

The trap here is confusing the primary goal of classification (determining appropriate security controls) with secondary benefits like cost reduction or compliance with a specific function (marketing) — candidates pick a plausible-sounding but narrow outcome instead of the core security purpose.

How to eliminate wrong answers

Option A is wrong because data classification does not improve access speed — it may actually add controls that affect access, but performance is not its goal. Option B is wrong because marketing compliance is a narrow, secondary use case; classification is driven by security, privacy, and regulatory needs, not marketing. Option D is wrong because reducing storage costs is a possible byproduct of retention policies informed by classification, but it is not the primary goal — cost optimization is downstream of the security and governance purpose.

163
MCQmedium

Which of the following are examples of sensitive PII? (Select all that apply.)

A.Phone number
B.Medical records
C.Social Security number
D.Name and email address
AnswerB, C

Medical records are sensitive PII because they combine an identifier with health data, revealing diagnoses, treatments or conditions. This falls within special-category data under GDPR and triggers stricter handling than ordinary personal data, satisfying the stem's requirement for sensitive rather than generic PII.

Why this answer

Sensitive PII includes data that, if disclosed, could cause harm or be used for identity theft. Medical records and Social Security numbers are classic examples of sensitive PII because they contain highly confidential information. Phone numbers and name/email address are generally considered PII but not necessarily sensitive PII on their own.

Exam trap

CC often tests the distinction between PII and sensitive PII; candidates may incorrectly select phone number or name/email as sensitive, not realizing that sensitivity depends on the potential for harm and regulatory definitions.

How to eliminate wrong answers

Option A is wrong because a phone number alone is typically considered standard PII, not sensitive PII, unless combined with other data. Option D is wrong because a name and email address are also standard PII; they are not inherently sensitive without additional context.

164
MCQeasy

Which of the following best describes the principle of confidentiality in the CIA triad?

A.Ensuring data is accurate and complete
B.Verifying the identity of users
C.Preventing unauthorized disclosure of information
D.Ensuring systems and data are accessible when needed
AnswerC

Confidentiality directly addresses unauthorised disclosure, ensuring information remains accessible only to those with legitimate access rights. This satisfies the stem's requirement by naming the specific security objective that prevents exposure of data to unauthorised parties, distinguishing it from integrity (unauthorised modification) and availability (disruption of access).

Why this answer

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encryption and access controls are primary mechanisms to enforce confidentiality.

165
MCQeasy

An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

A.Availability
B.Non-repudiation
C.Integrity
D.Confidentiality
AnswerD

Encryption at rest and in transit renders data unreadable to unauthorised parties, directly preventing disclosure. Confidentiality is the CIA principle concerned with restricting data access to approved subjects, so encrypting sensitive data satisfies that constraint rather than integrity or availability.

Why this answer

Encryption of data at rest and in transit directly protects data from unauthorized disclosure, which is the definition of confidentiality in the CIA triad. Encryption ensures that even if data is intercepted or accessed without authorization, it remains unreadable without the proper decryption key. This is the textbook control for the confidentiality principle.

Exam trap

The trap here is confusing confidentiality with integrity because encryption is sometimes described as 'protecting' data — candidates who do not distinguish between preventing unauthorized reading (confidentiality) and preventing unauthorized modification (integrity) may select the wrong principle.

How to eliminate wrong answers

Option A is wrong because availability concerns ensuring data and systems are accessible to authorized users when needed — encryption does not address uptime, redundancy, or denial-of-service resilience. Option B is wrong because non-repudiation is not part of the CIA triad at all; it is a separate security property typically addressed through digital signatures and audit logging. Option C is wrong because integrity concerns ensuring data has not been altered — while encryption can support integrity through authenticated encryption modes, the primary purpose of encrypting data at rest and in transit is confidentiality, not tamper detection.

166
MCQhard

After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?

A.Risk transfer
B.Risk acceptance
C.Risk avoidance
D.Risk mitigation
AnswerB

Risk acceptance means acknowledging a risk and choosing to bear the potential loss rather than mitigate it. The organisation identified the vulnerability but declined to patch it because of downtime concerns, deliberately retaining the exposure, which matches acceptance rather than avoidance, transference or mitigation.

Why this answer

Risk acceptance is the strategy of acknowledging a risk and choosing to take no action to prevent it, often because the cost of mitigation outweighs the potential impact. Here, the organization identified the vulnerability but consciously decided not to patch it due to downtime concerns, which is the textbook definition of accepting the risk. The breach that followed is the realized consequence of that accepted risk.

Exam trap

The trap here is confusing risk acceptance with risk mitigation, because candidates see that the organization 'identified' the vulnerability and assume any awareness implies action; the key is that no action was taken, which is acceptance.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial impact to a third party, typically through insurance or outsourcing, which did not occur here. Option C is wrong because risk avoidance means eliminating the activity or system that creates the risk entirely, such as decommissioning the web server, which the organization did not do. Option D is wrong because risk mitigation involves taking action to reduce the likelihood or impact of the risk, such as patching, applying compensating controls, or segmenting the network, none of which the organization performed.

167
MCQeasy

A hospital's compliance officer must decide how to protect patient records. The records must remain readable only to authorized clinicians while in storage and in transit. Which security principle is the compliance officer primarily applying?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerC

Confidentiality ensures information is not disclosed to unauthorized individuals, which directly matches the requirement that only authorized clinicians can read patient records. Protecting data in storage and transit through encryption and access controls is the classic application of this principle, so it is the correct choice for this scenario.

Why this answer

Confidentiality is the security principle that prevents unauthorized disclosure of information. The scenario requires that patient records remain readable only to authorized clinicians, both at rest and in transit, which is exactly what confidentiality controls such as encryption and access control provide. The other principles address availability, proof of origin, or protection from modification, none of which is the primary requirement described.

Exam trap

The trap here is confusing confidentiality with integrity, because both often use encryption, but only confidentiality addresses preventing unauthorized reading rather than unauthorized changes.

168
MCQmedium

An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?

A.Confidentiality
B.Integrity
C.Authentication
D.Availability
AnswerD

Redundant servers and failover maintain uptime when a component or power source fails, directly preserving access to systems and data. Availability is the CIA goal concerned with ensuring authorised users can reach resources when required.

Why this answer

Availability ensures that systems and data are accessible to authorized users when needed, and redundant servers with failover mechanisms directly support continuous operation during outages. This is the core goal of the availability pillar of the CIA triad. Confidentiality and integrity address different concerns, so availability is the correct answer.

Exam trap

The trap is that candidates may associate redundancy with integrity or confidentiality because both involve protecting data, but the question's focus on continuous operation during an outage clearly points to availability.

How to eliminate wrong answers

Option A is wrong because confidentiality focuses on preventing unauthorized access to data, typically through encryption, access controls, and classification, not on ensuring uptime. Option B is wrong because integrity ensures data is accurate and unaltered, using hashing, checksums, and digital signatures, which is unrelated to failover and redundancy. Option C is wrong because authentication verifies identity through credentials, MFA, or certificates, and is not one of the three CIA triad goals at all, making it a distractor.

← PreviousPage 3 of 3 · 168 questions total

Ready to test yourself?

Try a timed practice session using only Security Principles questions.