Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

⚠ Common exam trap

The trap is confusing authentication with confidentiality — candidates often pick authentication because it 'sounds like security,' but authentication is an identity-verification function, not the data-secrecy principle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confidentiality

Confidentiality is the CIA triad principle that ensures information is not disclosed to unauthorized individuals, systems, or processes. It is enforced through encryption, access controls, and data classification. Authentication verifies identity but does not itself guarantee confidentiality, and integrity and availability address different properties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authentication

    Why it's wrong here

    Authentication verifies an identity's claimed credentials; it does not govern whether data is disclosed to that identity afterwards. The option tempts because authentication is a prerequisite for access control. It would be correct if the question asked how a system confirms a user is who they claim to be before granting entry.

  • ✓

    Confidentiality

    Why this is correct

    Confidentiality directly prevents unauthorised disclosure by restricting data access to approved parties only. It is the CIA principle concerned with secrecy, unlike integrity (unauthorised modification) or availability (timely access). This satisfies the stem's requirement that data is not disclosed to unauthorised individuals.

  • ✗

    Integrity

    Why it's wrong here

    Integrity protects data from unauthorised modification, not from unauthorised disclosure. The option tempts because integrity and confidentiality are both CIA triad pillars often discussed together. It would be the correct choice if the question asked how to ensure data remains accurate and unaltered in storage or transit.

  • ✗

    Availability

    Why it's wrong here

    Availability ensures data and services remain accessible to authorised users, addressing uptime rather than disclosure. The option tempts because it is the third CIA triad pillar and sounds security-related. It would be correct if the question asked how to prevent denial-of-service or ensure systems remain reachable when needed.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.