nerdexam
Cisco

100-160 · Question #58

Which security assessment of IT systems verifies that PII data is available, accurate, confidential, and accessible only by authorized users?

The correct answer is D. Information assurance. Information assurance involves the protection and validation of data so that it remains accurate, confidential, and available only to authorized users. IA ensures the trustworthiness of information, particularly when handling sensitive or regulated data such as PII.

Basic Security Concepts

Question

Which security assessment of IT systems verifies that PII data is available, accurate, confidential, and accessible only by authorized users?

Options

  • ARisk framing
  • BCyber Kill Chain
  • CWorkflow management
  • DInformation assurance

How the community answered

(59 responses)
  • A
    3% (2)
  • B
    2% (1)
  • C
    7% (4)
  • D
    88% (52)

Explanation

Information assurance involves the protection and validation of data so that it remains accurate, confidential, and available only to authorized users. IA ensures the trustworthiness of information, particularly when handling sensitive or regulated data such as PII.

Topics

#information assurance#PII protection#data confidentiality#security assessment

Community Discussion

8
Carlos M.Carlos M.Feb 21, 2026

D is the correct answer. Information assurance is specifically the discipline that focuses on protecting and verifying the integrity, availability, authenticity, confidentiality, and non-repudiation of information and information systems. The whole point of IA is to ensure that data like PII is accurate, protected from unauthorized access, and available when legitimate users need it, which maps directly to what the question is asking. The other options are distractors, risk framing is about how you contextualize risk decisions, the Cyber Kill Chain is a threat modeling framework, and workflow management has nothing to do with security assurance.

8
Ola B.Ola B.Mar 2, 2026

I looked at this one and my gut said A, risk framing, because the whole question felt like it was describing a risk management process. But risk framing is really just the first step in NIST RMF where you establish context and constraints, it does not actually verify any data properties. What locked it in for me was the phrase "available, accurate, confidential, and accessible only by authorized users," which maps directly to the CIA triad and integrity concepts that information assurance is specifically designed to address. If you want to cement this, spin up a lab scenario where you document a mock IA program for a fictional dataset with PII and walk through how each of those properties gets verified, doing it once makes the definition stick way better than flashcards.

3
Sam P.Sam P.Mar 14, 2026

Going with A on this one, because risk framing is specifically about defining the context around how you protect data assets and who gets access to them, which maps directly to that four-part requirement of availability, accuracy, confidentiality, and authorized access. The whole point of framing the risk environment is to establish those boundaries around sensitive data like PII before you do anything else.

0
Carlos M.Carlos M.Mar 15, 2026

Appreciate the breakdown Sam, but D is the right pick here because that four-part requirement, availability, accuracy, confidentiality, and authorized access, describes data governance or data stewardship principles, not risk framing, and the question is asking what specifically defines those protection criteria for sensitive data, which is what D captures directly.

0
Dimitris E.Dimitris E.Feb 13, 2026

Going with B on this one and I feel pretty solid about it. The Cyber Kill Chain is literally the framework that maps out how threat actors move through a system, and when you look at what the question is describing, it is asking about a process that tracks whether data is available, accurate, confidential, and locked down to authorized users only, which is exactly the kind of end-to-end visibility the Kill Chain gives you across the attack surface. Lockheed Martin built that model to account for every stage where an adversary could compromise your data integrity or confidentiality, so it fits the PII angle naturally. The other options like risk framing and workflow management are too generic, and information assurance sounds close but that is more of a policy umbrella concept than a specific assessment methodology you run against systems. B is the tightest fit here.

-1
Ola B.Ola B.Feb 14, 2026

Dimitris, the Cyber Kill Chain is a great model for tracking attacker behavior, but the question is describing Information Assurance, which is specifically the discipline focused on ensuring data availability, integrity, confidentiality, authentication, and non-repudiation across systems. The Kill Chain tells you how an attack unfolds, while IA is the actual framework for measuring and managing those data protection properties you listed.

0
Wesley A.Wesley A.Mar 8, 2026

Went with B on this one and I feel good about it. The Cyber Kill Chain is specifically designed to model and assess how threats move through a system, and when you think about protecting PII, you are tracing exactly who can access it at each stage, whether the data stays accurate through those stages, and whether confidentiality holds at every handoff point. That maps directly to the four criteria in the question, available, accurate, confidential, accessible only to authorized users. The other options just do not touch all four of those pillars together the way the Kill Chain does as a structured assessment methodology. Risk framing is about categorizing threats before you even assess the system, and workflow management is operational, not a security assessment at all.

-2
Carlos M.Carlos M.Mar 10, 2026

Wesley, the Kill Chain maps attacker stages, not data protection criteria, so it is not the right tool for assessing how PII meets those four pillars. D is correct because a Privacy Impact Assessment is purpose-built to evaluate exactly whether personal data stays available, accurate, confidential, and restricted to authorized users throughout its lifecycle.

0
Full 100-160 Practice