ISC2 CC Security Principles Practice Question
Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?
⚠ Common exam trap
The trap is confusing authentication with confidentiality — candidates often pick authentication because it 'sounds like security,' but authentication is an identity-verification function, not the data-secrecy principle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
Confidentiality is the CIA triad principle that ensures information is not disclosed to unauthorized individuals, systems, or processes. It is enforced through encryption, access controls, and data classification. Authentication verifies identity but does not itself guarantee confidentiality, and integrity and availability address different properties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication
Why it's wrong here
Authentication verifies an identity's claimed credentials; it does not govern whether data is disclosed to that identity afterwards. The option tempts because authentication is a prerequisite for access control. It would be correct if the question asked how a system confirms a user is who they claim to be before granting entry.
- ✓
Confidentiality
Why this is correct
Confidentiality directly prevents unauthorised disclosure by restricting data access to approved parties only. It is the CIA principle concerned with secrecy, unlike integrity (unauthorised modification) or availability (timely access). This satisfies the stem's requirement that data is not disclosed to unauthorised individuals.
- ✗
Integrity
Why it's wrong here
Integrity protects data from unauthorised modification, not from unauthorised disclosure. The option tempts because integrity and confidentiality are both CIA triad pillars often discussed together. It would be the correct choice if the question asked how to ensure data remains accurate and unaltered in storage or transit.
- ✗
Availability
Why it's wrong here
Availability ensures data and services remain accessible to authorised users, addressing uptime rather than disclosure. The option tempts because it is the third CIA triad pillar and sounds security-related. It would be correct if the question asked how to prevent denial-of-service or ensure systems remain reachable when needed.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
CIA triad
The CIA triad is a foundational security model that guides organizations in protecting data through confidentiality, integrity, and availability.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.