mediumMultiple Select
ISC2 CC Practice Question: Which TWO of the following are primary goals of…
Which TWO of the following are primary goals of the security principle of confidentiality?
⚠ Common exam trap
Candidates often confuse the goals of confidentiality with those of integrity or availability, or mistaking supporting mechanisms like authentication for primary goals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protect data in transit
Option D (Protect data in transit) is correct because confidentiality requires safeguarding information while it moves across networks, typically achieved with encryption protocols such as TLS or IPsec so that eavesdroppers cannot read the contents. Option E (Prevent unauthorized disclosure) is correct because confidentiality is fundamentally defined as ensuring information is not made available or disclosed to unauthorized individuals, entities, or processes. Options A, B, and C do not belong: data accuracy is the goal of integrity, system uptime is an availability concern, and user authentication is an access-control mechanism that supports confidentiality but is not itself a primary confidentiality goal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure data accuracy
Why it's wrong here
Data accuracy belongs to integrity, which guards against unauthorised modification, not disclosure. Confidentiality's goals are preventing unauthorised access and disclosure, typically via encryption, access control and classification. Accuracy is tempting because corrupted records feel like a security failure, but integrity, not confidentiality, is the property that addresses it.
- ✗
Maintain system uptime
Why it's wrong here
Uptime is an availability objective, so it addresses whether systems and data remain accessible rather than preventing unauthorised disclosure. It is tempting because availability is a core pillar of the CIA triad and uptime metrics are widely tracked, but confidentiality is served by encryption, access control and data classification.
- ✗
Provide user authentication
Why it's wrong here
Authentication verifies a claimed identity, which supports access control; confidentiality itself concerns preventing unauthorised disclosure of data through encryption, classification and least privilege. It is tempting because authentication is a foundational security control and is often listed alongside confidentiality in awareness material.
- ✓
Protect data in transit
Why this is correct
Encryption protocols such as TLS and IPsec render intercepted traffic unreadable, so confidentiality is preserved even when data crosses untrusted networks. This directly satisfies the goal of shielding information from eavesdroppers during transmission, complementing at-rest protections.
- ✓
Prevent unauthorized disclosure
Why this is correct
Preventing unauthorised disclosure directly satisfies confidentiality's core constraint: ensuring information is accessible only to those with legitimate need. This mechanism restricts data exposure to approved parties, distinguishing confidentiality from integrity, which addresses unauthorised modification, and availability, which ensures timely access. It is therefore a primary goal.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.