hardMultiple Choice
ISC2 CC Practice Question: Refer to the exhibit
Exhibit
Mar 15 09:45:22 server sshd[1234]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2 Mar 15 09:45:23 server sshd[1235]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2 Mar 15 09:45:24 server sshd[1236]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2
Refer to the exhibit. Which security principle is being supported by the logging of these events?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accountability
Correct: D - Accountability. Logging provides a record of events that can be traced to specific sources, enabling accountability. Non-repudiation involves proof of actions by a user, but these logs do not prove user identity. Authentication and availability are not directly supported.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Availability
Why it's wrong here
Availability concerns ensuring systems and data remain accessible to authorised users, typically via redundancy, failover and backups. Event logging does not maintain uptime or restore service. Availability would be the supported principle if the exhibit showed load balancing, replication or disaster recovery measures keeping resources reachable.
- ✗
Authentication
Why it's wrong here
Authentication verifies a subject's claimed identity through credentials such as passwords, tokens or certificates. Logging occurs after identity is established, recording activity rather than proving who someone is. Authentication would be the correct principle if the exhibit showed a sign-in mechanism or credential validation process.
- ✗
Non-repudiation
Why it's wrong here
Logging records who performed an action, supporting accountability and audit trails, but non-repudiation requires cryptographic proof binding a party to an action, such as digital signatures. Logs alone can be altered or deleted. Non-repudiation is the right answer when signatures or tamper-evident evidence prevent someone denying an action.
- ✓
Accountability
Why this is correct
Logging ties each recorded action to an authenticated identity, so activity can later be attributed to a specific user or process. That traceable attribution is what supports accountability, the principle the exhibited event records demonstrate.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Accountability
Accountability is the security principle that ensures actions and identity are linked so that a person or system can be held responsible for their activities.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.