hardMultiple Choice
CISSP Practice Question: A security analyst discovers that an employee…
A security analyst discovers that an employee shared confidential customer data with an unauthorized third party. The analyst reports this to the CISO, who decides to terminate the employee. Which ethical principle from the (ISC)² Code of Ethics is most directly violated by the employee?
⚠ Common exam trap
Candidates often think that any leak of customer data violates 'Protect society, the common good, necessary public trust and confidence' because it affects the public or customers. However, because the employee is abusing the access and trust granted by their employer (the principal), the most direct violation is of the canon 'Provide diligent and competent service to principals'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide diligent and competent service to principals
Disclosing confidential customer or corporate data that an employee has access to via their employer violates the trust and privileges granted by the employer (the principal). According to the (ISC)² Code of Ethics, the canon 'Provide diligent and competent service to principals' requires members to respect the trust and privileges granted to them and to preserve the value of the principal's systems, applications, and information. Therefore, leaking confidential data directly violates this canon.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Provide diligent and competent service to principals
Why this is correct
While providing diligent and competent service to an employer (the principal) is a fundamental ethical duty, the act of an employee sharing confidential data extends beyond a mere breach of organizational loyalty. The primary ethical violation, in this context, transcends the duty solely to the principal because the compromised data often belongs to clients, customers, or citizens, not just the employer. Therefore, the direct impact on broader societal trust and individual privacy takes precedence over the duty owed exclusively to the organization.
- ✗
Protect society, the common good, necessary public trust and confidence, and the infrastructure
Why it's wrong here
Sharing confidential data directly undermines the public's trust and confidence in organizations and the security professionals safeguarding their information, which is a core tenet of Canon 1. This action erodes the common good by potentially exposing individuals to harm, compromising organizational integrity, and destabilizing the critical infrastructure that relies on secure data handling. Canon 1 mandates that protecting society and maintaining this essential trust is the paramount ethical responsibility for all CISSP professionals, making this the most direct and severe ethical breach.
- ✗
Advance and protect the profession
Why it's wrong here
Although sharing confidential data can indirectly tarnish the reputation of the cybersecurity profession, this canon is not the *primary* ethical breach in this scenario. Advancing and protecting the profession primarily involves upholding professional standards, sharing knowledge responsibly, and fostering a positive image for security practitioners through exemplary conduct. The direct harm from a data breach is inflicted upon the individuals whose data is exposed and the public's confidence, rather than the abstract concept of the profession itself.
- ✗
Act honorably, honestly, justly, responsibly, and legally
Why it's wrong here
While sharing confidential information is undoubtedly a dishonorable, dishonest, irresponsible, and illegal act, this canon describes the *manner* in which a professional should conduct themselves, rather than the specific *object* of protection in a data breach scenario. Canon 2 serves as a broad behavioral guideline, emphasizing personal integrity and adherence to legal standards. However, Canon 1 specifically addresses the direct harm to society, public trust, and critical infrastructure caused by such a breach, making it the more precise and primary ethical canon violated.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Code of ethics
A set of principles and rules that guide IT professionals to act with integrity, honesty, and responsibility in their work.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.