easyMultiple Select
ISC2 CC Practice Question: Which TWO of the following are fundamental…
Which TWO of the following are fundamental principles of information security that form the CIA triad?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
Confidentiality (A) is a core CIA triad principle because it ensures information is not disclosed to unauthorized individuals, systems, or processes, typically enforced through encryption, access controls, and classification. Integrity (B) is also a core CIA triad principle because it ensures data and systems remain accurate, complete, and protected from unauthorized modification, whether in storage or transit, using mechanisms like hashing, checksums, and digital signatures. Together with Availability, these three form the CIA triad, the foundational model for information security. Privacy (C) is a related concept concerning the appropriate handling of personal data, but it is not one of the three CIA triad principles. Non-repudiation (D) is a security property that prevents a party from denying an action, often achieved with digital signatures, but it is not part of the CIA triad. Accountability (E) supports security through auditing and traceability, but it is likewise not one of the three CIA triad pillars.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confidentiality
Why this is correct
Confidentiality ensures information is disclosed only to authorised parties, typically through encryption and access controls. It is one of the three CIA triad pillars, directly satisfying the stem's requirement for a fundamental information security principle.
- ✓
Integrity
Why this is correct
Integrity safeguards data accuracy and completeness against unauthorised modification, satisfying the CIA triad's requirement alongside confidentiality and availability. It ensures information remains trustworthy throughout storage and transmission, detecting or preventing alterations whether accidental or malicious. This directly answers the stem's demand for a fundamental CIA principle.
- ✗
Privacy
Why it's wrong here
Privacy governs appropriate handling of personal data and regulatory obligations, not one of the triad's three properties. It is tempting because confidentiality and privacy are often conflated, but privacy would be the correct focus when addressing data-protection compliance, not when identifying the CIA triad's constituent principles.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation proves an action occurred and cannot be denied, typically via digital signatures, but it is not a CIA triad property. It is tempting because it is a recognised security service, yet it would be correct when establishing legal proof of transactions, not when naming the triad's principles.
- ✗
Accountability
Why it's wrong here
Accountability assigns actions to a responsible entity through logging and auditing, supporting security but sitting outside the CIA triad's three named properties. It is tempting because it underpins governance and traceability, yet it would be correct when designing audit trails, not when naming the triad's fundamental principles.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
CIA triad
The CIA triad is a foundational security model that guides organizations in protecting data through confidentiality, integrity, and availability.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are principles of the CIA triad? (Select TWO.)
easy- ✓ A.Confidentiality
- ✓ B.Integrity
- C.Non-repudiation
- D.Accountability
- E.Authorization
Why A: Confidentiality (A) is a core principle of the CIA triad because it ensures that information is accessible only to authorized parties, typically enforced through encryption, access controls, and classification. Integrity (B) is also a core principle, guaranteeing that data remains accurate, complete, and unaltered except by authorized actions, supported by hashing, checksums, and version controls. Together with Availability, these three form the CIA triad, the foundational model for information security. Non-repudiation (C) is a related security property ensuring a party cannot deny an action, but it is not one of the three CIA principles. Accountability (D) and Authorization (E) are important access-control and governance concepts, yet neither is a member of the CIA triad.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.