Courseiva

CC · topic practice

Security Principles practice questions

Security Principles is the largest CC domain, covering the CIA triad, governance, risk management, security controls, and privacy. Questions are scenario-based: you read a short situation and identify which principle, control type, or risk response is being applied, or which CIA element a given safeguard primarily protects.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Principles

What the exam tests

What to know about Security Principles

Given a scenario, classify the control by type and function and name the risk response or CIA element involved. The single most important skill is reading what the control actually does, not what it sounds like, before choosing an answer.

Applying confidentiality, integrity, and availability to specific safeguards like file integrity monitoring and encryption

Classifying controls as physical, administrative, or technical, and as preventive, detective, corrective, or compensating

Matching risk responses: risk avoidance, mitigation, transference, and acceptance, including documented risk acceptance

Distinguishing governance elements such as policies, standards, procedures, baselines, and the ISC2 Code of Ethics

Watch out for

Common Security Principles exam traps

  • ▸Treating any documented decision to live with a risk as mitigation; accepting an isolated, compensating-controlled legacy system is risk acceptance
  • ▸Labeling a control by its mechanism rather than its function; a control can be technical yet detective, or physical yet preventive
  • ▸Confusing integrity with confidentiality; version control and file integrity monitoring protect data integrity, not secrecy

Practice set

Security Principles questions

20 questions · select your answer, then reveal the explanation

An employee uses a password and a one-time code from a mobile authenticator app to log in. Which authentication type is being used?

Which of the following is an example of a Type 2 authentication factor?

Which of the following is an example of a Type 2 authentication factor?

Which of the following is an example of Type 2 (possession) authentication?

Which of the following is considered sensitive Personally Identifiable Information (PII)?

An organization is developing a data classification policy. Which THREE of the following are common classification levels?

An organization requires employees to enter a password and then approve a push notification on their mobile device to access the corporate network. What type of authentication is this?

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Which of the following best describes a vulnerability in the context of risk management?

What is the primary purpose of a digital signature?

Which of the following is an example of a Type 2 authentication factor?

A security analyst is reviewing data handling procedures. Which THREE of the following are considered sensitive PII?

A company is classifying data and wants to ensure that personally identifiable information (PII) receives appropriate protection. Which two of the following are considered PII? (Choose two.)

A financial institution is implementing data classification to protect customer information. They have identified data that includes medical records and financial account numbers. Which three labels are most appropriate for this data? (Choose three.)

A small business owner implements a policy that requires all employees to lock their computers when leaving their desks. This policy is primarily an example of which type of control?

A hospital's IT director must select an access control model for the electronic health records system. Clinicians need access to patient records only when actively treating those patients, and the hospital wants to enforce least privilege with the least administrative overhead. Which access control model BEST meets these requirements?

A financial services firm wants to implement a defense-in-depth strategy for its online banking platform. The security architect proposes several controls. Which of the following controls is an example of a preventive physical control?

A security officer is classifying the controls protecting a new customer portal. She must identify controls that are administrative in nature rather than technical or physical. Which TWO of the following are administrative controls? (Choose two.)

A security manager is analyzing a risk scenario where a threat actor could exploit a known software flaw to cause a denial of service. The manager estimates that the likelihood of exploitation is high and the impact would be severe. Which term best describes the combination of the software flaw and the threat actor's potential to exploit it?

An employee receives an email that appears to be from the IT department, asking them to click a link and reset their password immediately due to a security breach. The employee suspects it is a phishing attempt. Which principle of security awareness is MOST relevant to this situation?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Principles sessions

Start a Security Principles only practice session

Every question in these sessions is drawn from the Security Principles domain — nothing else.

Related practice questions

Related CC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CC exam test about Security Principles?
Given a scenario, classify the control by type and function and name the risk response or CIA element involved. The single most important skill is reading what the control actually does, not what it sounds like, before choosing an answer.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Principles questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Principles domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CC topics?
Use the topic links above to move to related areas, or go back to the CC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CC exam covers. They are not copied from any real exam or dump site.