nerdexam
(ISC)2

CISSP · Question #1433

What BEST describes the confidentiality, integrity, availability triad?

The correct answer is A. A tool used to assist in understanding how to protect the organization's data. The CIA triad (Confidentiality, Integrity, Availability) is a foundational security model used as a guiding framework to help organizations understand and protect their data assets.

Submitted by yuriko_h· Mar 5, 2026Security and Risk Management

Question

What BEST describes the confidentiality, integrity, availability triad?

Options

  • AA tool used to assist in understanding how to protect the organization's data
  • BThe three-step approach to determine the risk level of an organization
  • CThe implementation of security systems to protect the organization's data
  • DA vulnerability assessment to see how well the organization's data is protected

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    7% (2)
  • C
    4% (1)
  • D
    4% (1)

Why each option

The CIA triad (Confidentiality, Integrity, Availability) is a foundational security model used as a guiding framework to help organizations understand and protect their data assets.

AA tool used to assist in understanding how to protect the organization's dataCorrect

The CIA triad is best described as a conceptual tool or model that assists organizations in understanding how to protect data by ensuring information is kept private (confidentiality), accurate and unaltered (integrity), and accessible when needed (availability). It serves as a framework for evaluating security policies and controls, not a specific implementation or assessment methodology.

BThe three-step approach to determine the risk level of an organization

The CIA triad is not a three-step risk determination process; risk assessment methodologies (such as NIST RMF or qualitative/quantitative risk analysis) are separate frameworks used to evaluate organizational risk levels.

CThe implementation of security systems to protect the organization's data

The CIA triad is a conceptual model and guiding framework, not the actual implementation of security systems; implementing security controls is a separate operational activity informed by the triad.

DA vulnerability assessment to see how well the organization's data is protected

A vulnerability assessment is a distinct security activity that involves scanning and evaluating systems for weaknesses, which is not what the CIA triad represents.

Concept tested: CIA triad definition and purpose in security

Source: https://www.nist.gov/system/files/documents/2017/05/09/SP800-12r1.pdf

Topics

#CIA triad#information security principles#security goals

Community Discussion

No community discussion yet for this question.

Full CISSP Practice