Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company implements a security measure to ensure that only authorized employees can view sensitive customer records. Which principle of the CIA triad does this measure primarily protect?

⚠ Common exam trap

It's easy for candidates to confuse confidentiality with integrity, thinking that preventing unauthorized changes is the same as preventing unauthorized viewing, but confidentiality is about secrecy, not data accuracy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Confidentiality

Confidentiality ensures that sensitive information is accessible only to authorized individuals. By restricting access to customer records to authorized employees, the company directly prevents unauthorized disclosure, which is the core goal of confidentiality in the CIA triad.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Confidentiality

    Why this is correct

    Confidentiality, a cornerstone of the CIA triad, ensures that information is accessible only to those authorized to view it. This principle directly addresses the company's security measure to limit access to specific employees, preventing unauthorized disclosure of sensitive data. Implementing strong access controls, encryption, and data classification are typical methods to uphold confidentiality, aligning perfectly with the goal of restricting information access.

  • Integrity

    Why it's wrong here

    Integrity, the 'I' in the CIA triad, is concerned with maintaining the accuracy, completeness, and consistency of data throughout its entire lifecycle. Its primary goal is to prevent unauthorized or accidental modification, alteration, or destruction of information, ensuring its trustworthiness. While access controls can indirectly support integrity by limiting who can *modify* data, the question specifically addresses restricting *viewing* access, which is a direct concern of confidentiality.

    When this WOULD be correct

    A question asking which CIA principle is primarily protected by a measure that uses hashing to verify that customer records have not been altered during transmission.

  • Availability

    Why it's wrong here

    Availability, another key component of the CIA triad, guarantees that authorized users can reliably access systems and data when needed. This principle prioritizes uptime, resilience, and timely access to resources, often through measures like redundancy, backups, and disaster recovery planning. It differs from the question's scenario by focusing on the continuous accessibility of resources rather than the specific restriction of *who* is authorized to view sensitive information.

    When this WOULD be correct

    A question stating: 'A company implements redundant servers and backup power to ensure customer records are always accessible. Which CIA principle does this protect?' would make availability correct.

  • Accountability

    Why it's wrong here

    Accountability is distinct from the CIA triad and focuses on ensuring that actions performed on a system or with data can be traced back to a specific individual. It involves mechanisms like auditing, logging, and non-repudiation to establish who did what, when, and where. While crucial for security governance and incident response, it does not directly define the initial restriction of *who* can access information, which is the core of the question's scenario.

    When this WOULD be correct

    A question asks: 'Which security principle ensures that actions can be traced back to a specific user?' In that context, Accountability would be the correct answer because it involves auditing and non-repudiation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

ConfidentialityCorrect answer

Why this is correct

Confidentiality, a cornerstone of the CIA triad, ensures that information is accessible only to those authorized to view it. This principle directly addresses the company's security measure to limit access to specific employees, preventing unauthorized disclosure of sensitive data. Implementing strong access controls, encryption, and data classification are typical methods to uphold confidentiality, aligning perfectly with the goal of restricting information access.

IntegrityWrong answer — click to see why

Why this is wrong here

Integrity ensures data accuracy and prevents unauthorized modification, not restriction of access. The question focuses on limiting who can view records, which is confidentiality.

★ When this WOULD be the correct answer

A question asking which CIA principle is primarily protected by a measure that uses hashing to verify that customer records have not been altered during transmission.

Why candidates choose this

Candidates may confuse 'authorized employees' with data accuracy, thinking integrity involves ensuring only authorized changes, but the core here is viewing, not modifying.

AvailabilityWrong answer — click to see why

Why this is wrong here

The question specifies that the measure ensures only authorized employees can view records, which directly protects confidentiality (preventing unauthorized access), not availability (ensuring access when needed).

★ When this WOULD be the correct answer

A question stating: 'A company implements redundant servers and backup power to ensure customer records are always accessible. Which CIA principle does this protect?' would make availability correct.

Why candidates choose this

Candidates may confuse 'access control' with 'availability' because both involve access, but availability focuses on uptime and reliability, not authorization.

AccountabilityWrong answer — click to see why

Why this is wrong here

Accountability is not a principle of the CIA triad; the CIA triad consists of Confidentiality, Integrity, and Availability. This question specifically asks about the CIA triad, so Accountability is not a valid option.

★ When this WOULD be the correct answer

A question asks: 'Which security principle ensures that actions can be traced back to a specific user?' In that context, Accountability would be the correct answer because it involves auditing and non-repudiation.

Why candidates choose this

Candidates may confuse Accountability with Confidentiality because both involve controlling access to data, but Accountability focuses on tracking who did what, not on preventing unauthorized viewing.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.