Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

An attacker gains access to a company's email system and reads confidential customer emails. Which security principle has been compromised?

⚠ Common exam trap

Many candidates confuse confidentiality with integrity, mistakenly thinking that any unauthorized access to data implies data modification, but the core violation in this scenario is the unauthorized disclosure of information, not its alteration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Confidentiality

Confidentiality is the security principle that ensures data is accessible only to authorized users. When an attacker reads confidential customer emails without authorization, the confidentiality of that data has been breached, as the information was exposed to an unintended party.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Integrity

    Why it's wrong here

    Integrity focuses on safeguarding the accuracy and completeness of data, ensuring it remains unaltered and trustworthy throughout its lifecycle. While an attacker *could* potentially modify emails after gaining access, the question specifically states "gains access," which primarily implies unauthorized viewing or reading. There is no indication that the data itself was changed or corrupted, making integrity not the primary violation in this specific context.

    When this WOULD be correct

    A question where an attacker modifies email content or deletes messages without authorization, asking which security principle is violated.

  • Availability

    Why it's wrong here

    An attacker gaining access to an email system does not inherently mean the system or data became unavailable to legitimate users. Availability ensures that authorized users have timely and uninterrupted access to information and resources when needed. The scenario describes an unauthorized party *accessing* the system, not preventing authorized users from doing so, thus availability is not the primary security principle violated.

  • Confidentiality

    Why this is correct

    The scenario directly describes a breach of confidentiality, as an unauthorized attacker has gained access to private email communications. Confidentiality is the principle that prevents the unauthorized disclosure of information, ensuring that only authorized individuals or systems can view or access sensitive data. This compromise means the secrecy and privacy of the email content have been violated by an unapproved party.

  • Non-repudiation

    Why it's wrong here

    Non-repudiation provides irrefutable proof of an action or event, preventing a sender from denying they sent a message or a receiver from denying they received it. This principle is typically enforced through mechanisms like digital signatures or robust audit trails to establish accountability for actions. The attacker gaining unauthorized access to read emails is a breach of secrecy, not a situation where a party is denying an action they performed.

    When this WOULD be correct

    Non-repudiation would be correct in a scenario where an attacker sends a fraudulent email and later denies sending it, and the question asks which principle ensures the sender cannot deny the action. For example: 'An employee claims they never sent a sensitive email, but digital signatures prove otherwise. Which security principle is demonstrated?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

ConfidentialityCorrect answer

Why this is correct

The scenario directly describes a breach of confidentiality, as an unauthorized attacker has gained access to private email communications. Confidentiality is the principle that prevents the unauthorized disclosure of information, ensuring that only authorized individuals or systems can view or access sensitive data. This compromise means the secrecy and privacy of the email content have been violated by an unapproved party.

IntegrityWrong answer — click to see why

Why this is wrong here

Integrity ensures data is not altered or tampered with, but the scenario describes unauthorized reading of emails, not modification.

★ When this WOULD be the correct answer

A question where an attacker modifies email content or deletes messages without authorization, asking which security principle is violated.

Why candidates choose this

Candidates may confuse confidentiality with integrity, thinking that unauthorized access inherently implies data has been compromised in integrity.

Non-repudiationWrong answer — click to see why

Why this is wrong here

Non-repudiation ensures that a party cannot deny having performed an action, such as sending an email. Reading emails does not involve denying an action; the breach is about unauthorized access to confidential data, which violates confidentiality.

★ When this WOULD be the correct answer

Non-repudiation would be correct in a scenario where an attacker sends a fraudulent email and later denies sending it, and the question asks which principle ensures the sender cannot deny the action. For example: 'An employee claims they never sent a sensitive email, but digital signatures prove otherwise. Which security principle is demonstrated?'

Why candidates choose this

Candidates may confuse non-repudiation with confidentiality because both involve email security. They might think that reading emails without authorization relates to non-repudiation, but non-repudiation is about accountability and proof of origin, not access control.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.