easyMultiple Select
ISC2 CC Practice Question: Which TWO of the following are core components of…
Which TWO of the following are core components of the CIA triad?
⚠ Common exam trap
The trap here is conflating security services (Authentication, Authorization, Non-repudiation) with the CIA triad components — candidates pick Authentication or Non-repudiation because they sound foundational, but only Confidentiality, Integrity, and Availability are the triad.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
The CIA triad is the foundational information security model consisting of Confidentiality, Integrity, and Availability, so option C (Confidentiality) is correct because it ensures data is disclosed only to authorized parties through mechanisms such as encryption, access controls, and classification. Option E (Availability) is also correct because it ensures systems and data are accessible to authorized users when needed, supported by controls like redundancy, backups, and DDoS mitigation. The unmarked options do not belong because Authentication (A), Authorization (D), and Non-repudiation (B) are distinct security services and principles that support or extend beyond the CIA triad rather than being its core components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication
Why it's wrong here
Authentication verifies identity, which supports access control but is not itself confidentiality, integrity or availability. It would be correct in a question about the AAA model or identity assurance, where proving who a subject is forms the first component.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation proves an action occurred and cannot be denied, which is a property of accountability and digital signatures rather than the CIA triad. It would be correct in a question about cryptographic assurance or audit evidence, where proof of origin and delivery is the requirement.
- ✓
Confidentiality
Why this is correct
Confidentiality is a core CIA triad component, ensuring data is disclosed only to authorised parties. It satisfies the stem's requirement by naming one of the three foundational security objectives, alongside integrity and availability. Encryption, access controls and classification enforce it, preventing unauthorised disclosure across Microsoft Entra ID and other systems.
- ✗
Authorization
Why it's wrong here
Authorization governs what an authenticated principal may do, which is an access-control function, not one of the three CIA triad properties. It would be the right answer in a question about AAA or access management, where authentication, authorization and accounting are the components.
- ✓
Availability
Why this is correct
Availability ensures timely and reliable access to data and systems for authorised users, completing the CIA triad alongside confidentiality and integrity. It directly satisfies the stem's requirement for a core CIA component, addressing the constraint that systems remain accessible when needed rather than merely protected from disclosure or alteration.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.