Courseiva
hardMultiple Choice

ISC2 CC Practice Question: Refer to the exhibit

Exhibit

Mar 15 09:45:22 server sshd[1234]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2
Mar 15 09:45:23 server sshd[1235]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2
Mar 15 09:45:24 server sshd[1236]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2

Refer to the exhibit. Which security principle is being supported by the logging of these events?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accountability

Correct: D - Accountability. Logging provides a record of events that can be traced to specific sources, enabling accountability. Non-repudiation involves proof of actions by a user, but these logs do not prove user identity. Authentication and availability are not directly supported.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Availability

    Why it's wrong here

    Availability concerns ensuring systems and data remain accessible to authorised users, typically via redundancy, failover and backups. Event logging does not maintain uptime or restore service. Availability would be the supported principle if the exhibit showed load balancing, replication or disaster recovery measures keeping resources reachable.

  • ✗

    Authentication

    Why it's wrong here

    Authentication verifies a subject's claimed identity through credentials such as passwords, tokens or certificates. Logging occurs after identity is established, recording activity rather than proving who someone is. Authentication would be the correct principle if the exhibit showed a sign-in mechanism or credential validation process.

  • ✗

    Non-repudiation

    Why it's wrong here

    Logging records who performed an action, supporting accountability and audit trails, but non-repudiation requires cryptographic proof binding a party to an action, such as digital signatures. Logs alone can be altered or deleted. Non-repudiation is the right answer when signatures or tamper-evident evidence prevent someone denying an action.

  • ✓

    Accountability

    Why this is correct

    Logging ties each recorded action to an authenticated identity, so activity can later be attributed to a specific user or process. That traceable attribution is what supports accountability, the principle the exhibited event records demonstrate.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.