nerdexam
(ISC)2

CGRC · Question #158

Which of the following statements about the availability concept of Information security management is true? Response:

The correct answer is B. It ensures reliable and timely access to resources.. Availability in information security ensures that authorized users have reliable and timely access to information and resources when needed.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following statements about the availability concept of Information security management is true? Response:

Options

  • AIt ensures that modifications are not made to data by unauthorized personnel or processes .
  • BIt ensures reliable and timely access to resources.
  • CIt determines actions and behaviors of a single individual within a system.
  • DIt ensures that unauthorized modifications are not made to data by authorized personnel or

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    91% (31)
  • D
    6% (2)

Why each option

Availability in information security ensures that authorized users have reliable and timely access to information and resources when needed.

AIt ensures that modifications are not made to data by unauthorized personnel or processes .

This describes integrity, which ensures data is not improperly modified, rather than availability.

BIt ensures reliable and timely access to resources.Correct

Availability, as one of the pillars of information security (CIA triad), specifically ensures that information and information systems are accessible and usable by authorized users when required. This includes ensuring that systems are operational, data is retrievable, and resources are functioning in a timely and consistent manner.

CIt determines actions and behaviors of a single individual within a system.

This describes accountability or non-repudiation, which attributes actions to individuals, not availability.

DIt ensures that unauthorized modifications are not made to data by authorized personnel or

This describes integrity, as it focuses on preventing unauthorized data modifications, even if done by authorized personnel, which is distinct from ensuring access.

Concept tested: Availability in information security

Source: https://csrc.nist.gov/glossary/term/availability

Topics

#Availability#Information Security Concepts#CIA Triad

Community Discussion

No community discussion yet for this question.

Full CGRC Practice