CIA Triad Availability with Backups and Disaster Recovery
A company regularly performs automated backups of its critical databases and has a disaster recovery plan to restore operations quickly after a system failure. Which security principle is primarily being addressed by these measures?
Quick Answer
The answer is availability. Automated backups and a disaster recovery plan directly uphold the availability principle of the CIA triad by ensuring that critical databases can be restored and operations resumed quickly after a system failure, guaranteeing that systems and data remain accessible to authorized users when needed. On the Microsoft Security, Compliance, and Identity Fundamentals SC-900 exam, this concept tests your ability to distinguish availability from integrity (which protects data accuracy) and confidentiality (which restricts unauthorized access). A common trap is confusing backups with integrity, but remember: backups are about restoring access after a failure, not preventing data tampering. For a quick memory tip, think of the acronym BAD: Backups and Disaster recovery ensure Availability against Downtime.
⚠ Common exam trap
Many candidates confuse 'backups and disaster recovery' with 'data protection' broadly, incorrectly selecting Confidentiality or Integrity, when the primary goal is to restore access and uptime, which is the essence of Availability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Availability
Automated backups and a disaster recovery plan directly support the Availability principle of the CIA triad by ensuring that critical databases can be restored and operations resumed quickly after a system failure. Availability guarantees that systems and data are accessible to authorized users when needed, and these measures minimize downtime and data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confidentiality
Why it's wrong here
Confidentiality ensures data is accessible only to authorized users; backups and disaster recovery are not primarily about access control.
When this WOULD be correct
A question asking which principle is addressed by encrypting backup data at rest and in transit, or by implementing access controls on backup storage, would make confidentiality the correct answer.
- ✗
Integrity
Why it's wrong here
Integrity ensures data is not altered by unauthorized parties; while backups can help restore to a known good state, the primary goal here is ensuring continued access to data and services.
When this WOULD be correct
A question asking which principle is addressed by implementing checksums, hashing, or digital signatures to detect data tampering during transmission or storage would make integrity the correct answer.
- ✓
Availability
Why this is correct
Availability ensures systems and data are accessible when needed. Backups and disaster recovery plans directly support availability by enabling recovery from failures.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation provides proof of actions (e.g., digital signatures) and is not addressed by backups or disaster recovery.
When this WOULD be correct
Non-repudiation would be the correct answer in a scenario where the question asks about measures to prove that a specific user performed an action, such as implementing digital signatures or audit trails to prevent denial of transactions or data modifications.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓AvailabilityCorrect answer▾
Why this is correct
Availability ensures systems and data are accessible when needed. Backups and disaster recovery plans directly support availability by enabling recovery from failures.
✗ConfidentialityWrong answer — click to see why▾
Why this is wrong here
Automated backups and disaster recovery plans are designed to ensure systems and data can be restored after a failure, directly supporting availability. Confidentiality is about preventing unauthorized access, not about recovery from failures.
★ When this WOULD be the correct answer
A question asking which principle is addressed by encrypting backup data at rest and in transit, or by implementing access controls on backup storage, would make confidentiality the correct answer.
Why candidates choose this
Candidates may confuse the protection of backup data (which involves confidentiality) with the purpose of having backups (which is availability), leading them to select confidentiality incorrectly.
✗IntegrityWrong answer — click to see why▾
Why this is wrong here
Automated backups and disaster recovery plans are designed to ensure systems and data are recoverable after failures, directly supporting availability. Integrity focuses on preventing unauthorized modification, which is not the primary goal of these measures.
★ When this WOULD be the correct answer
A question asking which principle is addressed by implementing checksums, hashing, or digital signatures to detect data tampering during transmission or storage would make integrity the correct answer.
Why candidates choose this
Candidates may confuse backups with data protection against corruption, mistakenly thinking backups ensure data integrity rather than availability.
✗Non-repudiationWrong answer — click to see why▾
Why this is wrong here
Non-repudiation ensures that actions cannot be denied by the parties involved, typically through digital signatures or audit logs. Automated backups and disaster recovery plans do not address non-repudiation; they focus on restoring data and systems after a failure, which supports availability.
★ When this WOULD be the correct answer
Non-repudiation would be the correct answer in a scenario where the question asks about measures to prove that a specific user performed an action, such as implementing digital signatures or audit trails to prevent denial of transactions or data modifications.
Why candidates choose this
Candidates might confuse disaster recovery with maintaining a record of actions, thinking that backups provide proof of past states. However, non-repudiation is about accountability and irrefutable evidence, not about restoring operations.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Disaster recovery plan
A Disaster Recovery Plan (DRP) is a documented, structured approach that outlines how an organization can quickly resume critical IT systems and operations after a disruptive event.
Key term
CIA triad
The CIA triad is a foundational security model that guides organizations in protecting data through confidentiality, integrity, and availability.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company hosts a mission-critical customer portal on Azure virtual machines. To ensure continuous availability, they deploy the application across two separate Azure regions. If one region experiences a failure, traffic is automatically routed to the other region with minimal disruption. Which security goal is primarily being addressed by this architecture?
easy- A.Confidentiality
- B.Integrity
- ✓ C.Availability
- D.Non-repudiation
Why C: Deploying a mission-critical application across two Azure regions with automatic traffic routing directly addresses the security goal of availability. This architecture ensures that if one region fails, the application remains accessible from the other region, minimizing downtime. Azure Traffic Manager or Azure Front Door can be used to route traffic based on priority or latency, providing high availability and disaster recovery.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.