NEW
Font size
WorksheetsCIA Triad Fundamentals (Questions 1-8)
Total questions: 75
Worksheet time: 1hrs 15mins
Which security principle focuses on preventing unauthorized disclosure of sensitive information?
Authentication verifies user identities
Confidentiality restricts access to authorized users
Availability ensures systems are up and responsive
Authorization assigns user permissions and roles
Integrity protects data accuracy and consistency
A company encrypts customer credit card numbers before storing them in a database. Which CIA principle is primarily being addressed?
Non-repudiation by binding actions to users
Integrity by detecting unauthorized changes
Availability by reducing service downtime
Confidentiality by protecting private data
Accounting by tracking user activity
Hashing a file to verify it has not been altered supports which security objective?
Integrity through change detection
Confidentiality through controlled access
Availability through redundancy and uptime
Authorization through role assignment
Authentication through identity proof
A system administrator implements redundant servers to prevent downtime during hardware failure. Which CIA component is being strengthened?
Integrity for accurate records
Authentication for login verification
Availability for continuous service
Authorization for access control lists
Confidentiality for private information
Which control would most likely reduce system performance if implemented aggressively?
Regular data backups overnight
Load balancing across multiple servers
Failover clustering for resilience
Strong integrity checks and hashing
Redundant storage for fault tolerance
Which scenario best illustrates a CIA trade-off?
Restricting system access during maintenance
Limiting login attempts on a site
Encrypting backups stored offline
Applying patches only after testing
Updating antivirus definitions daily
A retail shop stores customer purchase history and email addresses. Which CIA principle is most critical to protect this data?
Confidentiality for private information
Integrity for accurate transactions
Availability for service continuity
Non-repudiation for user accountability
Accounting for audit trail creation
Preventing unauthorized modification of inventory records primarily supports which principle?
Authorization for role-based access
Availability for uptime and access
Confidentiality for secrecy controls
Integrity for tamper resistance
Authentication for identity checks
A retail website experiences downtime during a holiday sale due to high traffic. Which CIA principle failed?
Confidentiality
Authorization
Availability
Integrity
Authentication
Which technology MOST directly supports confidentiality during web transactions?
Checksums
Load balancers
SSL/TLS
Version control
RAID arrays
IoT devices raise ethical concerns primarily because they:
Operate autonomously
Are expensive to maintain
Collect continuous data
Use wireless connections
Require frequent updates
Which IoT concern involves uncertainty about how collected data is handled?
Data usage transparency
Integrity loss
Device availability
Latency
Network congestion
Sharing IoT data with advertisers without user consent violates which principle MOST directly?
Accounting
Availability
Integrity
Confidentiality
Authorization
Cookies and third-party trackers primarily impact which security concern?
Network redundancy
Physical security
Data confidentiality
Hardware integrity
System availability
Which technique allows websites to track users without cookies?
Private browsing
Load balancing
Hashing
Encryption
Browser fingerprinting
Clearing cookies helps protect users primarily by:
Increasing integrity
Improving availability
Encrypting traffic
Limiting persistent tracking
Preventing malware
Which browser feature reduces exposure to tracking data?
Failover clustering
Load balancing
RAID storage
Private browsing
Version control
Passive analysis is BEST described as:
Sending test packets to a server
Exploiting a known vulnerability
Observing traffic without interaction
Modifying system configurations
Performing credential testing
Which activity is an example of active analysis?
Observing DNS queries
Monitoring system uptime
Running a vulnerability scan
Capturing network traffic
Reviewing log files
Why is passive analysis generally considered safer?
It improves availability
It uses encryption
It avoids system interaction
It authenticates users
It blocks malware
Authorized hacking is BEST defined as:
Approved testing with permission
Illegal access for educational purposes
Attacks against public systems
Exploitation of known vulnerabilities
Any hacking performed by professionals
Unauthorized hacking differs from authorized hacking because it is:
More effective
Illegal and malicious
Less technical
Used in education
Conducted by insiders
A penetration tester discovers a vulnerability and reports it without exploiting it. This action supports:
Confidentiality
Availability
Defensive security
Unauthorized access
Malicious intent
The PRIMARY goal of penetration testing is to:
Shut down systems
Steal sensitive data
Identify weaknesses safely
Monitor employee activity
Replace security tools
Which AAA component answers the question “Who are you?”
Confidentiality
Authentication
Integrity
Accounting
Authorization
Granting a user access to specific files after login is an example of:
Accounting
Authorization
Integrity
Authentication
Availability
Logging user activity for auditing purposes supports:
Confidentiality
Accounting
Availability
Integrity
Authorization
Which process MUST occur before authorization?
Integrity checking
Accounting
Authentication
Non-repudiation
Encryption
Non-repudiation ensures that:
Access is restricted
Systems remain online
Data is encrypted
Logs are deleted
Users cannot deny actions
Which AAA component MOST directly supports non-repudiation?
Authorization
Availability
Authentication
Integrity
Accounting
Digital signatures support non-repudiation by:
Limiting user access
Increasing redundancy
Verifying sender identity
Logging system uptime
Encrypting backups
PII is BEST described as:
Technical system data
Any public information
Encrypted network traffic
Information identifying an individual
Device configuration details
Which data set is MOST likely considered PII?
CPU architecture
Full name and birthdate
IP subnet
Operating system
Browser version
Race or gender alone is usually not PII because it:
Is encrypted by default
Is protected by law
Cannot identify a specific person
Is always public data
Is considered metadata
When combined with other data, race and gender may become:
Integrity data
Availability data
System metadata
PII
Authorization records
Which control BEST protects PII stored in a database?
Monitoring uptime
Redundant servers
Encryption
Load balancing
Version control
A system that records login times and actions is supporting:
Authorization only
Authentication only
Availability
Confidentiality
Accounting
Which CIA principle MOST affected by a DDoS attack?
Availability
Authentication
Integrity
Confidentiality
Authorization
Load balancing primarily improves:
Non-repudiation
Authentication
Availability
Confidentiality
Integrity
Version control systems primarily protect:
Availability
Accounting
Integrity
Confidentiality
Authorization
Which method BEST ensures data has not been altered in transit?
Encryption
Load balancing
Hashing
Authentication
Redundancy
MFA primarily strengthens which CIA component?
Accounting
Confidentiality
Non-repudiation
Integrity
Availability
ACLs are MOST closely associated with:
Authentication
Integrity
Authorization
Accounting
Availability
Which action BEST supports ethical IoT deployment?
Clearly disclose data usage
Share data freely
Disable encryption
Remove authentication
Collect maximum data
Browser fingerprinting is difficult to avoid because it:
Uses system characteristics
Disables scripts
Requires malware
Relies on encryption
Blocks cookies
Which security model links identity, permissions, and activity tracking?
CIA
AAA
OSI
PKI
Zero Trust
Accounting logs are MOST useful for:
Preventing attacks
Encrypting data
Incident investigations
Improving availability
Blocking malware
Which principle ensures systems are usable during peak demand?
Integrity
Availability
Confidentiality
Authorization
Authentication
A company limits admin access to prevent accidental changes. This supports:
Confidentiality only
Integrity only
Availability only
Authorization and integrity
Authentication and accounting
Which statement BEST summarizes the relationship between AAA and non-repudiation?
Authentication removes logging
Authorization prevents tracking
Accounting enables non-repudiation
AAA weakens integrity
AAA replaces encryption
Bikes, Boards, and Beyond experiences a situation where customer orders are still visible, but several product prices were changed without approval. Which CIA principle has MOST clearly been violated?
Confidentiality
Authentication
Availability
Integrity
Authorization
An IoT-enabled fitness tracker collects location, heart rate, and sleep data. The company later sells anonymized data to advertisers without informing users. Which concern is MOST directly raised?
Availability risk
Ethical data usage
System redundancy
Authentication failure
Load imbalance
A cybersecurity analyst monitors network traffic patterns from a mirrored port without sending any packets to production systems. What type of analysis is being performed?
Active reconnaissance
Passive analysis
Authorization testing
Penetration testing
Vulnerability exploitation
A student runs a vulnerability scanner against a school server without permission as part of a “learning experiment.” How should this activity be classified?
Authorized hacking
Ethical hacking
Defensive security
Unauthorized hacking
Passive analysis
During peak holiday traffic, a retail website crashes despite having strong encryption and access controls. Which CIA improvement would MOST directly address this issue?
Redundant servers
Tighter ACLs
Data classification
Multi-factor authentication
Stronger hashing algorithms
An administrator reviews detailed logs showing which employees accessed customer records and when. Which AAA component is being utilized?
Confidentiality
Authentication
Accounting
Integrity
Authorization
A customer claims they never approved a refund transaction, but digital logs show their authenticated account completed the action. Which concept prevents the customer from denying the action?
Confidentiality
Availability
Integrity
Non-repudiation
Authorization
A website user clears cookies regularly but still sees targeted advertisements across multiple sites. Which tracking method is MOST likely responsible?
SSL certificates
Session cookies
Load balancing
Tracking pixels
Browser fingerprinting
A penetration tester is hired to identify vulnerabilities but must avoid causing downtime or data loss. What is the PRIMARY objective of this engagement?
Collecting PII
Proving system compromise
Stress-testing availability
Availability data
Safely identifying weaknesses
A database stores employee names, employee IDs, and department names. Individually, these fields are harmless, but together they can identify specific employees. How should this data be classified?
Non-sensitive metadata
Anonymous data
PII
Integrity-only data
Availability data
A question asks about protecting customer payment data, limiting who can access it, and encrypting it during transmission. Which Security+ 701 domain is MOST directly being assessed?
General Security Concepts
Security Architecture
Security Operations
Governance, Risk, and Compliance
Cryptography and PKI
A scenario describes a company hiring a third party to legally test systems for vulnerabilities. Which domain is MOST relevant?
Security Architecture
Threats, Vulnerabilities, and Mitigations
General Security Concepts
Security Operations
Cryptography and PKI
A company wants to prevent unauthorized access to customer records while minimizing impact on user experience. Which control is the BEST choice?
Daily backups
Load balancing
Network monitoring
Multi-factor authentication
Full disk encryption
A website is currently offline due to excessive traffic. Which action should be taken FIRST?
Implement MFA
Enable detailed logging
Add redundant servers
Update access controls
Reclassify data
An attacker floods a retail website with traffic, preventing customers from checking out. What is the IMPACT?
Data corruption
Loss of confidentiality
Integrity verification failure
Unauthorized access
Loss of availability
A company has no DDoS protection configured on its public website. This represents a:
Threat
Vulnerability
Mitigation
Impact
Control
An IoT doorbell records video continuously and uploads footage to the cloud without clear user disclosure. What is the PRIMARY concern?
System availability
Ethical data collection
Load balancing
Authorization failure
Integrity validation
An IoT thermostat shares usage data with third parties only after users agree during setup. Which principle is being supported?
Authentication
Transparency
Availability
Integrity
Redundancy
A company enforces extremely strict access controls that slow employee productivity. This is an example of a trade-off affecting:
Integrity and availability
Privacy and compliance
Confidentiality and availability
Accounting and non-repudiation
Authorization and authentication
A business accepts moderate risk to keep systems highly accessible during peak hours. This decision MOST directly prioritizes:
Authorization
Availability
Confidentiality
Accounting
Integrity
Which option is NOT an example of authorization?
Granting admin privileges
Verifying a password
Assigning file permissions
Restricting access to folders
Limiting system functions
Which control primarily ensures integrity rather than confidentiality?
Encryption
MFA
Hashing
Access control lists
Data classification
In the AAA process, which logical order is correct for a user accessing a system?
Authentication, Authorization, Accounting
Authorization, Authentication, Accounting
Authorization, Accounting, Authentication
Authentication, Accounting, Authorization
Accounting, Authorization, Authentication
A security team enables authenticated logs for admin actions. What benefit is MOST directly achieved?
Encrypted data in transit
Automatic privilege escalation
Verified user identity in records
Improved availability monitoring
Real-time malware blocking
An organization reduces transparency about data collection to simplify onboarding. Which risk increases MOST?
Token expiration frequency
Hash collision probability
System performance degradation
User consent violations
Backup window length
