ISC2 CC Security Principles Practice Question
Which of the following best describes the principle of confidentiality in the CIA triad?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventing unauthorized disclosure of information
Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encryption and access controls are primary mechanisms to enforce confidentiality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensuring data is accurate and complete
Why it's wrong here
Accuracy and completeness describe integrity, not confidentiality. It is tempting because integrity is the neighbouring CIA triad pillar, and data-quality controls genuinely are the correct answer when a question asks how to prevent unauthorised modification rather than disclosure.
- ✗
Verifying the identity of users
Why it's wrong here
Identity verification is authentication, a prerequisite control, not confidentiality itself. It is tempting because authentication frequently gates access to confidential data, and it would be the correct answer to a question asking how a system confirms who a user claims to be before granting access.
- ✓
Preventing unauthorized disclosure of information
Why this is correct
Confidentiality directly addresses unauthorised disclosure, ensuring information remains accessible only to those with legitimate access rights. This satisfies the stem's requirement by naming the specific security objective that prevents exposure of data to unauthorised parties, distinguishing it from integrity (unauthorised modification) and availability (disruption of access).
- ✗
Ensuring systems and data are accessible when needed
Why it's wrong here
Availability covers timely access to systems and data, not restricting disclosure. It is tempting because availability is the third CIA pillar and denial-of-service resistance genuinely is the correct answer when a question asks how to keep services reachable during attack or failure.
Go deeper
Related to this question
Key term
Confidentiality Integrity and Availability
The CIA Triad is a foundational security model that ensures data is kept secret, unaltered, and accessible when needed.
Key term
CIA triad
The CIA triad is a foundational security model that guides organizations in protecting data through confidentiality, integrity, and availability.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.