Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

Which of the following best describes the principle of confidentiality in the CIA triad?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preventing unauthorized disclosure of information

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encryption and access controls are primary mechanisms to enforce confidentiality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring data is accurate and complete

    Why it's wrong here

    Accuracy and completeness describe integrity, not confidentiality. It is tempting because integrity is the neighbouring CIA triad pillar, and data-quality controls genuinely are the correct answer when a question asks how to prevent unauthorised modification rather than disclosure.

  • ✗

    Verifying the identity of users

    Why it's wrong here

    Identity verification is authentication, a prerequisite control, not confidentiality itself. It is tempting because authentication frequently gates access to confidential data, and it would be the correct answer to a question asking how a system confirms who a user claims to be before granting access.

  • ✓

    Preventing unauthorized disclosure of information

    Why this is correct

    Confidentiality directly addresses unauthorised disclosure, ensuring information remains accessible only to those with legitimate access rights. This satisfies the stem's requirement by naming the specific security objective that prevents exposure of data to unauthorised parties, distinguishing it from integrity (unauthorised modification) and availability (disruption of access).

  • ✗

    Ensuring systems and data are accessible when needed

    Why it's wrong here

    Availability covers timely access to systems and data, not restricting disclosure. It is tempting because availability is the third CIA pillar and denial-of-service resistance genuinely is the correct answer when a question asks how to keep services reachable during attack or failure.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.