nerdexam
(ISC)2

CGRC · Question #235

You are responsible for network and information security at a metropolitan police station. The most important concern is that unauthorized parties are not able to access dat

The correct answer is B. Confidentiality. The scenario describes the primary security concern as preventing unauthorized access to data. This specific aspect of information security, ensuring data is accessible only to authorized entities, is known as confidentiality.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

You are responsible for network and information security at a metropolitan police station. The most important concern is that unauthorized parties are not able to access dat

Options

  • AWhat is this called?
  • BConfidentiality
  • CEncryption
  • DIntegrity
  • EAvailability

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    94% (49)
  • C
    2% (1)

Why each option

The scenario describes the primary security concern as preventing unauthorized access to data. This specific aspect of information security, ensuring data is accessible only to authorized entities, is known as confidentiality.

AWhat is this called?

'What is this called?' is a question, not a security principle or concern.

BConfidentialityCorrect

Confidentiality is the assurance that information is not disclosed to unauthorized individuals, entities, or processes. In a police station setting, preventing unauthorized parties from accessing sensitive data like suspect information or ongoing investigation details is a paramount concern, directly aligning with the definition of confidentiality.

CEncryption

'Encryption' is a method used to achieve confidentiality, but it is not the security principle itself.

DIntegrity

'Integrity' ensures that data has not been altered or destroyed in an unauthorized manner, which is different from preventing unauthorized access.

EAvailability

'Availability' ensures that authorized users can access information and systems when needed, which is a different security objective than preventing unauthorized access.

Concept tested: Definition of confidentiality (CIA triad)

Source: https://csrc.nist.gov/glossary/term/confidentiality

Topics

#Confidentiality#Information Security Principles#Data Protection

Community Discussion

No community discussion yet for this question.

Full CGRC Practice