wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CIA Triad Fundamentals (Questions 1-8)

Total questions: 75

Worksheet time: 1hrs 15mins

Name
Class
Date
1.

Which security principle focuses on preventing unauthorized disclosure of sensitive information?

a)

Authentication verifies user identities

b)

Confidentiality restricts access to authorized users

c)

Availability ensures systems are up and responsive

d)

Authorization assigns user permissions and roles

e)

Integrity protects data accuracy and consistency

2.

A company encrypts customer credit card numbers before storing them in a database. Which CIA principle is primarily being addressed?

a)

Non-repudiation by binding actions to users

b)

Integrity by detecting unauthorized changes

c)

Availability by reducing service downtime

d)

Confidentiality by protecting private data

e)

Accounting by tracking user activity

3.

Hashing a file to verify it has not been altered supports which security objective?

a)

Integrity through change detection

b)

Confidentiality through controlled access

c)

Availability through redundancy and uptime

d)

Authorization through role assignment

e)

Authentication through identity proof

4.

A system administrator implements redundant servers to prevent downtime during hardware failure. Which CIA component is being strengthened?

a)

Integrity for accurate records

b)

Authentication for login verification

c)

Availability for continuous service

d)

Authorization for access control lists

e)

Confidentiality for private information

5.

Which control would most likely reduce system performance if implemented aggressively?

a)

Regular data backups overnight

b)

Load balancing across multiple servers

c)

Failover clustering for resilience

d)

Strong integrity checks and hashing

e)

Redundant storage for fault tolerance

6.

Which scenario best illustrates a CIA trade-off?

a)

Restricting system access during maintenance

b)

Limiting login attempts on a site

c)

Encrypting backups stored offline

d)

Applying patches only after testing

e)

Updating antivirus definitions daily

7.

A retail shop stores customer purchase history and email addresses. Which CIA principle is most critical to protect this data?

a)

Confidentiality for private information

b)

Integrity for accurate transactions

c)

Availability for service continuity

d)

Non-repudiation for user accountability

e)

Accounting for audit trail creation

8.

Preventing unauthorized modification of inventory records primarily supports which principle?

a)

Authorization for role-based access

b)

Availability for uptime and access

c)

Confidentiality for secrecy controls

d)

Integrity for tamper resistance

e)

Authentication for identity checks

9.

A retail website experiences downtime during a holiday sale due to high traffic. Which CIA principle failed?

a)

Confidentiality

b)

Authorization

c)

Availability

d)

Integrity

e)

Authentication

10.

Which technology MOST directly supports confidentiality during web transactions?

a)

Checksums

b)

Load balancers

c)

SSL/TLS

d)

Version control

e)

RAID arrays

11.

IoT devices raise ethical concerns primarily because they:

a)

Operate autonomously

b)

Are expensive to maintain

c)

Collect continuous data

d)

Use wireless connections

e)

Require frequent updates

12.

Which IoT concern involves uncertainty about how collected data is handled?

a)

Data usage transparency

b)

Integrity loss

c)

Device availability

d)

Latency

e)

Network congestion

13.

Sharing IoT data with advertisers without user consent violates which principle MOST directly?

a)

Accounting

b)

Availability

c)

Integrity

d)

Confidentiality

e)

Authorization

14.

Cookies and third-party trackers primarily impact which security concern?

a)

Network redundancy

b)

Physical security

c)

Data confidentiality

d)

Hardware integrity

e)

System availability

15.

Which technique allows websites to track users without cookies?

a)

Private browsing

b)

Load balancing

c)

Hashing

d)

Encryption

e)

Browser fingerprinting

16.

Clearing cookies helps protect users primarily by:

a)

Increasing integrity

b)

Improving availability

c)

Encrypting traffic

d)

Limiting persistent tracking

e)

Preventing malware

17.

Which browser feature reduces exposure to tracking data?

a)

Failover clustering

b)

Load balancing

c)

RAID storage

d)

Private browsing

e)

Version control

18.

Passive analysis is BEST described as:

a)

Sending test packets to a server

b)

Exploiting a known vulnerability

c)

Observing traffic without interaction

d)

Modifying system configurations

e)

Performing credential testing

19.

Which activity is an example of active analysis?

a)

Observing DNS queries

b)

Monitoring system uptime

c)

Running a vulnerability scan

d)

Capturing network traffic

e)

Reviewing log files

20.

Why is passive analysis generally considered safer?

a)

It improves availability

b)

It uses encryption

c)

It avoids system interaction

d)

It authenticates users

e)

It blocks malware

21.

Authorized hacking is BEST defined as:

a)

Approved testing with permission

b)

Illegal access for educational purposes

c)

Attacks against public systems

d)

Exploitation of known vulnerabilities

e)

Any hacking performed by professionals

22.

Unauthorized hacking differs from authorized hacking because it is:

a)

More effective

b)

Illegal and malicious

c)

Less technical

d)

Used in education

e)

Conducted by insiders

23.

A penetration tester discovers a vulnerability and reports it without exploiting it. This action supports:

a)

Confidentiality

b)

Availability

c)

Defensive security

d)

Unauthorized access

e)

Malicious intent

24.

The PRIMARY goal of penetration testing is to:

a)

Shut down systems

b)

Steal sensitive data

c)

Identify weaknesses safely

d)

Monitor employee activity

e)

Replace security tools

25.

Which AAA component answers the question “Who are you?”

a)

Confidentiality

b)

Authentication

c)

Integrity

d)

Accounting

e)

Authorization

26.

Granting a user access to specific files after login is an example of:

a)

Accounting

b)

Authorization

c)

Integrity

d)

Authentication

e)

Availability

27.

Logging user activity for auditing purposes supports:

a)

Confidentiality

b)

Accounting

c)

Availability

d)

Integrity

e)

Authorization

28.

Which process MUST occur before authorization?

a)

Integrity checking

b)

Accounting

c)

Authentication

d)

Non-repudiation

e)

Encryption

29.

Non-repudiation ensures that:

a)

Access is restricted

b)

Systems remain online

c)

Data is encrypted

d)

Logs are deleted

e)

Users cannot deny actions

30.

Which AAA component MOST directly supports non-repudiation?

a)

Authorization

b)

Availability

c)

Authentication

d)

Integrity

e)

Accounting

31.

Digital signatures support non-repudiation by:

a)

Limiting user access

b)

Increasing redundancy

c)

Verifying sender identity

d)

Logging system uptime

e)

Encrypting backups

32.

PII is BEST described as:

a)

Technical system data

b)

Any public information

c)

Encrypted network traffic

d)

Information identifying an individual

e)

Device configuration details

33.

Which data set is MOST likely considered PII?

a)

CPU architecture

b)

Full name and birthdate

c)

IP subnet

d)

Operating system

e)

Browser version

34.

Race or gender alone is usually not PII because it:

a)

Is encrypted by default

b)

Is protected by law

c)

Cannot identify a specific person

d)

Is always public data

e)

Is considered metadata

35.

When combined with other data, race and gender may become:

a)

Integrity data

b)

Availability data

c)

System metadata

d)

PII

e)

Authorization records

36.

Which control BEST protects PII stored in a database?

a)

Monitoring uptime

b)

Redundant servers

c)

Encryption

d)

Load balancing

e)

Version control

37.

A system that records login times and actions is supporting:

a)

Authorization only

b)

Authentication only

c)

Availability

d)

Confidentiality

e)

Accounting

38.

Which CIA principle MOST affected by a DDoS attack?

a)

Availability

b)

Authentication

c)

Integrity

d)

Confidentiality

e)

Authorization

39.

Load balancing primarily improves:

a)

Non-repudiation

b)

Authentication

c)

Availability

d)

Confidentiality

e)

Integrity

40.

Version control systems primarily protect:

a)

Availability

b)

Accounting

c)

Integrity

d)

Confidentiality

e)

Authorization

41.

Which method BEST ensures data has not been altered in transit?

a)

Encryption

b)

Load balancing

c)

Hashing

d)

Authentication

e)

Redundancy

42.

MFA primarily strengthens which CIA component?

a)

Accounting

b)

Confidentiality

c)

Non-repudiation

d)

Integrity

e)

Availability

43.

ACLs are MOST closely associated with:

a)

Authentication

b)

Integrity

c)

Authorization

d)

Accounting

e)

Availability

44.

Which action BEST supports ethical IoT deployment?

a)

Clearly disclose data usage

b)

Share data freely

c)

Disable encryption

d)

Remove authentication

e)

Collect maximum data

45.

Browser fingerprinting is difficult to avoid because it:

a)

Uses system characteristics

b)

Disables scripts

c)

Requires malware

d)

Relies on encryption

e)

Blocks cookies

46.

Which security model links identity, permissions, and activity tracking?

a)

CIA

b)

AAA

c)

OSI

d)

PKI

e)

Zero Trust

47.

Accounting logs are MOST useful for:

a)

Preventing attacks

b)

Encrypting data

c)

Incident investigations

d)

Improving availability

e)

Blocking malware

48.

Which principle ensures systems are usable during peak demand?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authorization

e)

Authentication

49.

A company limits admin access to prevent accidental changes. This supports:

a)

Confidentiality only

b)

Integrity only

c)

Availability only

d)

Authorization and integrity

e)

Authentication and accounting

50.

Which statement BEST summarizes the relationship between AAA and non-repudiation?

a)

Authentication removes logging

b)

Authorization prevents tracking

c)

Accounting enables non-repudiation

d)

AAA weakens integrity

e)

AAA replaces encryption

51.

Bikes, Boards, and Beyond experiences a situation where customer orders are still visible, but several product prices were changed without approval. Which CIA principle has MOST clearly been violated?

a)

Confidentiality

b)

Authentication

c)

Availability

d)

Integrity

e)

Authorization

52.

An IoT-enabled fitness tracker collects location, heart rate, and sleep data. The company later sells anonymized data to advertisers without informing users. Which concern is MOST directly raised?

a)

Availability risk

b)

Ethical data usage

c)

System redundancy

d)

Authentication failure

e)

Load imbalance

53.

A cybersecurity analyst monitors network traffic patterns from a mirrored port without sending any packets to production systems. What type of analysis is being performed?

a)

Active reconnaissance

b)

Passive analysis

c)

Authorization testing

d)

Penetration testing

e)

Vulnerability exploitation

54.

A student runs a vulnerability scanner against a school server without permission as part of a “learning experiment.” How should this activity be classified?

a)

Authorized hacking

b)

Ethical hacking

c)

Defensive security

d)

Unauthorized hacking

e)

Passive analysis

55.

During peak holiday traffic, a retail website crashes despite having strong encryption and access controls. Which CIA improvement would MOST directly address this issue?

a)

Redundant servers

b)

Tighter ACLs

c)

Data classification

d)

Multi-factor authentication

e)

Stronger hashing algorithms

56.

An administrator reviews detailed logs showing which employees accessed customer records and when. Which AAA component is being utilized?

a)

Confidentiality

b)

Authentication

c)

Accounting

d)

Integrity

e)

Authorization

57.

A customer claims they never approved a refund transaction, but digital logs show their authenticated account completed the action. Which concept prevents the customer from denying the action?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Non-repudiation

e)

Authorization

58.

A website user clears cookies regularly but still sees targeted advertisements across multiple sites. Which tracking method is MOST likely responsible?

a)

SSL certificates

b)

Session cookies

c)

Load balancing

d)

Tracking pixels

e)

Browser fingerprinting

59.

A penetration tester is hired to identify vulnerabilities but must avoid causing downtime or data loss. What is the PRIMARY objective of this engagement?

a)

Collecting PII

b)

Proving system compromise

c)

Stress-testing availability

d)

Availability data

e)

Safely identifying weaknesses

60.

A database stores employee names, employee IDs, and department names. Individually, these fields are harmless, but together they can identify specific employees. How should this data be classified?

a)

Non-sensitive metadata

b)

Anonymous data

c)

PII

d)

Integrity-only data

e)

Availability data

61.

A question asks about protecting customer payment data, limiting who can access it, and encrypting it during transmission. Which Security+ 701 domain is MOST directly being assessed?

a)

General Security Concepts

b)

Security Architecture

c)

Security Operations

d)

Governance, Risk, and Compliance

e)

Cryptography and PKI

62.

A scenario describes a company hiring a third party to legally test systems for vulnerabilities. Which domain is MOST relevant?

a)

Security Architecture

b)

Threats, Vulnerabilities, and Mitigations

c)

General Security Concepts

d)

Security Operations

e)

Cryptography and PKI

63.

A company wants to prevent unauthorized access to customer records while minimizing impact on user experience. Which control is the BEST choice?

a)

Daily backups

b)

Load balancing

c)

Network monitoring

d)

Multi-factor authentication

e)

Full disk encryption

64.

A website is currently offline due to excessive traffic. Which action should be taken FIRST?

a)

Implement MFA

b)

Enable detailed logging

c)

Add redundant servers

d)

Update access controls

e)

Reclassify data

65.

An attacker floods a retail website with traffic, preventing customers from checking out. What is the IMPACT?

a)

Data corruption

b)

Loss of confidentiality

c)

Integrity verification failure

d)

Unauthorized access

e)

Loss of availability

66.

A company has no DDoS protection configured on its public website. This represents a:

a)

Threat

b)

Vulnerability

c)

Mitigation

d)

Impact

e)

Control

67.

An IoT doorbell records video continuously and uploads footage to the cloud without clear user disclosure. What is the PRIMARY concern?

a)

System availability

b)

Ethical data collection

c)

Load balancing

d)

Authorization failure

e)

Integrity validation

68.

An IoT thermostat shares usage data with third parties only after users agree during setup. Which principle is being supported?

a)

Authentication

b)

Transparency

c)

Availability

d)

Integrity

e)

Redundancy

69.

A company enforces extremely strict access controls that slow employee productivity. This is an example of a trade-off affecting:

a)

Integrity and availability

b)

Privacy and compliance

c)

Confidentiality and availability

d)

Accounting and non-repudiation

e)

Authorization and authentication

70.

A business accepts moderate risk to keep systems highly accessible during peak hours. This decision MOST directly prioritizes:

a)

Authorization

b)

Availability

c)

Confidentiality

d)

Accounting

e)

Integrity

71.

Which option is NOT an example of authorization?

a)

Granting admin privileges

b)

Verifying a password

c)

Assigning file permissions

d)

Restricting access to folders

e)

Limiting system functions

72.

Which control primarily ensures integrity rather than confidentiality?

a)

Encryption

b)

MFA

c)

Hashing

d)

Access control lists

e)

Data classification

73.

In the AAA process, which logical order is correct for a user accessing a system?

a)

Authentication, Authorization, Accounting

b)

Authorization, Authentication, Accounting

c)

Authorization, Accounting, Authentication

d)

Authentication, Accounting, Authorization

e)

Accounting, Authorization, Authentication

74.

A security team enables authenticated logs for admin actions. What benefit is MOST directly achieved?

a)

Encrypted data in transit

b)

Automatic privilege escalation

c)

Verified user identity in records

d)

Improved availability monitoring

e)

Real-time malware blocking

75.

An organization reduces transparency about data collection to simplify onboarding. Which risk increases MOST?

a)

Token expiration frequency

b)

Hash collision probability

c)

System performance degradation

d)

User consent violations

e)

Backup window length