SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company implements a security measure to ensure that only authorized employees can view sensitive customer records. Which principle of the CIA triad does this measure primarily protect?
⚠ Common exam trap
It's easy for candidates to confuse confidentiality with integrity, thinking that preventing unauthorized changes is the same as preventing unauthorized viewing, but confidentiality is about secrecy, not data accuracy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
Confidentiality ensures that sensitive information is accessible only to authorized individuals. By restricting access to customer records to authorized employees, the company directly prevents unauthorized disclosure, which is the core goal of confidentiality in the CIA triad.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confidentiality
Why this is correct
Confidentiality, a cornerstone of the CIA triad, ensures that information is accessible only to those authorized to view it. This principle directly addresses the company's security measure to limit access to specific employees, preventing unauthorized disclosure of sensitive data. Implementing strong access controls, encryption, and data classification are typical methods to uphold confidentiality, aligning perfectly with the goal of restricting information access.
- ✗
Integrity
Why it's wrong here
Integrity, the 'I' in the CIA triad, is concerned with maintaining the accuracy, completeness, and consistency of data throughout its entire lifecycle. Its primary goal is to prevent unauthorized or accidental modification, alteration, or destruction of information, ensuring its trustworthiness. While access controls can indirectly support integrity by limiting who can *modify* data, the question specifically addresses restricting *viewing* access, which is a direct concern of confidentiality.
When this WOULD be correct
A question asking which CIA principle is primarily protected by a measure that uses hashing to verify that customer records have not been altered during transmission.
- ✗
Availability
Why it's wrong here
Availability, another key component of the CIA triad, guarantees that authorized users can reliably access systems and data when needed. This principle prioritizes uptime, resilience, and timely access to resources, often through measures like redundancy, backups, and disaster recovery planning. It differs from the question's scenario by focusing on the continuous accessibility of resources rather than the specific restriction of *who* is authorized to view sensitive information.
When this WOULD be correct
A question stating: 'A company implements redundant servers and backup power to ensure customer records are always accessible. Which CIA principle does this protect?' would make availability correct.
- ✗
Accountability
Why it's wrong here
Accountability is distinct from the CIA triad and focuses on ensuring that actions performed on a system or with data can be traced back to a specific individual. It involves mechanisms like auditing, logging, and non-repudiation to establish who did what, when, and where. While crucial for security governance and incident response, it does not directly define the initial restriction of *who* can access information, which is the core of the question's scenario.
When this WOULD be correct
A question asks: 'Which security principle ensures that actions can be traced back to a specific user?' In that context, Accountability would be the correct answer because it involves auditing and non-repudiation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓ConfidentialityCorrect answer▾
Why this is correct
Confidentiality, a cornerstone of the CIA triad, ensures that information is accessible only to those authorized to view it. This principle directly addresses the company's security measure to limit access to specific employees, preventing unauthorized disclosure of sensitive data. Implementing strong access controls, encryption, and data classification are typical methods to uphold confidentiality, aligning perfectly with the goal of restricting information access.
✗IntegrityWrong answer — click to see why▾
Why this is wrong here
Integrity ensures data accuracy and prevents unauthorized modification, not restriction of access. The question focuses on limiting who can view records, which is confidentiality.
★ When this WOULD be the correct answer
A question asking which CIA principle is primarily protected by a measure that uses hashing to verify that customer records have not been altered during transmission.
Why candidates choose this
Candidates may confuse 'authorized employees' with data accuracy, thinking integrity involves ensuring only authorized changes, but the core here is viewing, not modifying.
✗AvailabilityWrong answer — click to see why▾
Why this is wrong here
The question specifies that the measure ensures only authorized employees can view records, which directly protects confidentiality (preventing unauthorized access), not availability (ensuring access when needed).
★ When this WOULD be the correct answer
A question stating: 'A company implements redundant servers and backup power to ensure customer records are always accessible. Which CIA principle does this protect?' would make availability correct.
Why candidates choose this
Candidates may confuse 'access control' with 'availability' because both involve access, but availability focuses on uptime and reliability, not authorization.
✗AccountabilityWrong answer — click to see why▾
Why this is wrong here
Accountability is not a principle of the CIA triad; the CIA triad consists of Confidentiality, Integrity, and Availability. This question specifically asks about the CIA triad, so Accountability is not a valid option.
★ When this WOULD be the correct answer
A question asks: 'Which security principle ensures that actions can be traced back to a specific user?' In that context, Accountability would be the correct answer because it involves auditing and non-repudiation.
Why candidates choose this
Candidates may confuse Accountability with Confidentiality because both involve controlling access to data, but Accountability focuses on tracking who did what, not on preventing unauthorized viewing.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
Key term
Confidentiality Integrity and Availability
The CIA Triad is a foundational security model that ensures data is kept secret, unaltered, and accessible when needed.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.