Courseiva
easyMultiple Select

ISC2 CC Practice Question: Which TWO of the following are core components of…

Which TWO of the following are core components of the CIA triad?

⚠ Common exam trap

The trap here is conflating security services (Authentication, Authorization, Non-repudiation) with the CIA triad components — candidates pick Authentication or Non-repudiation because they sound foundational, but only Confidentiality, Integrity, and Availability are the triad.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confidentiality

The CIA triad is the foundational information security model consisting of Confidentiality, Integrity, and Availability, so option C (Confidentiality) is correct because it ensures data is disclosed only to authorized parties through mechanisms such as encryption, access controls, and classification. Option E (Availability) is also correct because it ensures systems and data are accessible to authorized users when needed, supported by controls like redundancy, backups, and DDoS mitigation. The unmarked options do not belong because Authentication (A), Authorization (D), and Non-repudiation (B) are distinct security services and principles that support or extend beyond the CIA triad rather than being its core components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authentication

    Why it's wrong here

    Authentication verifies identity, which supports access control but is not itself confidentiality, integrity or availability. It would be correct in a question about the AAA model or identity assurance, where proving who a subject is forms the first component.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation proves an action occurred and cannot be denied, which is a property of accountability and digital signatures rather than the CIA triad. It would be correct in a question about cryptographic assurance or audit evidence, where proof of origin and delivery is the requirement.

  • ✓

    Confidentiality

    Why this is correct

    Confidentiality is a core CIA triad component, ensuring data is disclosed only to authorised parties. It satisfies the stem's requirement by naming one of the three foundational security objectives, alongside integrity and availability. Encryption, access controls and classification enforce it, preventing unauthorised disclosure across Microsoft Entra ID and other systems.

  • ✗

    Authorization

    Why it's wrong here

    Authorization governs what an authenticated principal may do, which is an access-control function, not one of the three CIA triad properties. It would be the right answer in a question about AAA or access management, where authentication, authorization and accounting are the components.

  • ✓

    Availability

    Why this is correct

    Availability ensures timely and reliable access to data and systems for authorised users, completing the CIA triad alongside confidentiality and integrity. It directly satisfies the stem's requirement for a core CIA component, addressing the constraint that systems remain accessible when needed rather than merely protected from disclosure or alteration.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.