Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A security analyst is explaining the core principles of information security to a new team member. Which principle ensures that data is not modified by unauthorized parties?

⚠ Common exam trap

It's easy for candidates to confuse integrity with confidentiality, mistakenly thinking that encryption (which protects confidentiality) also prevents modification, but encryption alone does not guarantee data has not been altered—integrity requires separate controls like hashing or digital signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Integrity

The principle of integrity ensures that data remains accurate and unaltered during storage, processing, or transmission, except by authorized entities. In the context of information security, integrity is specifically concerned with preventing unauthorized modification, deletion, or creation of data. This is often enforced through mechanisms such as hashing (e.g., SHA-256), digital signatures, and checksums (e.g., CRC32) that detect any tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Confidentiality

    Why it's wrong here

    Confidentiality is the security principle focused on preventing unauthorized disclosure or access to sensitive information. Its primary objective is to ensure that only authorized individuals, entities, or systems can view, read, or learn the content of specific data. While essential for privacy and secrecy, measures like encryption and access control lists are designed to restrict visibility, not to prevent the data from being modified by an authorized (or even unauthorized, if access is gained) party once it has been accessed or stored.

    When this WOULD be correct

    A question asks: 'Which principle ensures that data is not disclosed to unauthorized individuals?' In that context, confidentiality is the correct answer.

  • Integrity

    Why this is correct

    Integrity is the fundamental security principle that ensures data remains accurate, complete, and unaltered by unauthorized parties throughout its lifecycle. It guarantees that information has not been tampered with, either accidentally or maliciously, maintaining its trustworthiness and reliability. Mechanisms such as cryptographic hashing, digital signatures, and robust access controls are employed to detect or prevent unauthorized modifications, thereby preserving the validity and consistency of the data.

  • Availability

    Why it's wrong here

    Availability is the security principle that ensures authorized users can reliably access information and resources when and where they are needed, without undue interruption or delay. This principle focuses on the uptime, operational readiness, and responsiveness of systems and data, often achieved through redundancy, disaster recovery planning, and robust network infrastructure. However, availability does not inherently protect the content of the data from unauthorized changes; it merely guarantees the ability to reach and utilize it.

    When this WOULD be correct

    In a scenario where a company experiences a DDoS attack that prevents users from accessing a critical application, the principle being compromised is availability. A question asking which principle ensures that systems are up and running when required would have availability as the correct answer.

  • Non-repudiation

    Why it's wrong here

    Non-repudiation is a security principle that provides undeniable proof of the origin or delivery of data, ensuring that a party cannot falsely deny having sent a message or performed an action. It typically relies on mechanisms like digital signatures and audit trails to establish accountability and trust in transactions. While vital for legal and contractual enforceability, its primary function is to prevent denial of involvement, rather than directly protecting data from unauthorized modification or alteration itself.

    When this WOULD be correct

    A question asks: 'Which principle ensures that a sender cannot deny having sent a message?' In that context, non-repudiation is correct because it provides proof of origin or delivery.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

IntegrityCorrect answer

Why this is correct

Integrity is the fundamental security principle that ensures data remains accurate, complete, and unaltered by unauthorized parties throughout its lifecycle. It guarantees that information has not been tampered with, either accidentally or maliciously, maintaining its trustworthiness and reliability. Mechanisms such as cryptographic hashing, digital signatures, and robust access controls are employed to detect or prevent unauthorized modifications, thereby preserving the validity and consistency of the data.

ConfidentialityWrong answer — click to see why

Why this is wrong here

Confidentiality ensures data is accessible only to authorized users, but it does not prevent unauthorized modification; integrity is the principle that protects data from unauthorized alteration.

★ When this WOULD be the correct answer

A question asks: 'Which principle ensures that data is not disclosed to unauthorized individuals?' In that context, confidentiality is the correct answer.

Why candidates choose this

Candidates may confuse confidentiality with integrity because both involve protecting data, but confidentiality focuses on secrecy, not on preventing changes.

AvailabilityWrong answer — click to see why

Why this is wrong here

Availability ensures that data and systems are accessible when needed, but it does not protect against unauthorized modification. The principle that prevents data from being altered by unauthorized parties is integrity.

★ When this WOULD be the correct answer

In a scenario where a company experiences a DDoS attack that prevents users from accessing a critical application, the principle being compromised is availability. A question asking which principle ensures that systems are up and running when required would have availability as the correct answer.

Why candidates choose this

Candidates may confuse availability with integrity because both are part of the CIA triad, and they might think that ensuring data is available also means it hasn't been tampered with, but availability focuses on access, not modification.

Non-repudiationWrong answer — click to see why

Why this is wrong here

Non-repudiation ensures that a party cannot deny having performed an action (e.g., signing a document), not that data remains unmodified. The question asks about preventing unauthorized modification, which is integrity.

★ When this WOULD be the correct answer

A question asks: 'Which principle ensures that a sender cannot deny having sent a message?' In that context, non-repudiation is correct because it provides proof of origin or delivery.

Why candidates choose this

Candidates may confuse non-repudiation with integrity because both involve data authenticity, but non-repudiation focuses on accountability for actions, not data modification.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.