nerdexam
(ISC)2

CISSP · Question #158

Refer to the information below to answer the question. During the investigation of a security incident, it is determined that an unauthorized individual accessed a system which hosts a database contai

The correct answer is A. Unauthorized database changes. When an unauthorized individual accesses a financial database, the primary concern beyond data viewing is whether the attacker also modified, deleted, or corrupted the data, which represents an integrity violation.

Submitted by jordan8· Mar 5, 2026Security Operations

Question

Refer to the information below to answer the question. During the investigation of a security incident, it is determined that an unauthorized individual accessed a system which hosts a database containing financial information. Aside from the potential records which may have been viewed, which of the following should be the PRIMARY concern regarding the database information?

Options

  • AUnauthorized database changes
  • BIntegrity of security logs
  • CAvailability of the database
  • DConfidentiality of the incident

How the community answered

(34 responses)
  • A
    82% (28)
  • B
    3% (1)
  • C
    9% (3)
  • D
    6% (2)

Why each option

When an unauthorized individual accesses a financial database, the primary concern beyond data viewing is whether the attacker also modified, deleted, or corrupted the data, which represents an integrity violation.

AUnauthorized database changesCorrect

Unauthorized database changes represent an integrity threat, which is the primary concern because an attacker with access could have altered, deleted, or inserted financial records, causing potentially irreversible harm to the accuracy and trustworthiness of the data. Unlike mere viewing, unauthorized modifications to financial data can result in fraud, regulatory violations, and corrupted business decisions. Data integrity must be verified and restored before the database can be trusted for further use.

BIntegrity of security logs

While log integrity is important to the investigation, it is a secondary concern related to the forensic process rather than the primary concern about the database information itself.

CAvailability of the database

Availability of the database is a concern if the system is taken offline or disrupted, but the scenario does not indicate a denial-of-service condition, making it a lower priority than potential data tampering.

DConfidentiality of the incident

Confidentiality of the incident refers to keeping the investigation private, which is a procedural concern and not directly related to the primary risk posed to the database information by the unauthorized access.

Concept tested: Data integrity threats from unauthorized database access

Source: https://csrc.nist.gov/glossary/term/integrity

Topics

#data integrity#unauthorized access#incident response#CIA triad

Community Discussion

No community discussion yet for this question.

Full CISSP Practice