nerdexam
GIAC

GSEC · Question #355

Which of the following statements about the availability concept of Information security management is true?

The correct answer is A. It ensures reliable and timely access to resources. The availability pillar of the CIA triad guarantees that authorized users can reliably and timely access systems and data when needed. It is distinct from confidentiality and integrity.

Incident Handling, Risk, and Governance

Question

Which of the following statements about the availability concept of Information security management is true?

Options

  • AIt ensures reliable and timely access to resources.
  • BIt determines actions and behaviors of a single individual within a system.
  • CIt ensures that unauthorized modifications are not made to data by authorized personnel or
  • DIt ensures that modifications are not made to data by unauthorized personnel or processes.

How the community answered

(15 responses)
  • A
    73% (11)
  • B
    7% (1)
  • C
    13% (2)
  • D
    7% (1)

Why each option

The availability pillar of the CIA triad guarantees that authorized users can reliably and timely access systems and data when needed. It is distinct from confidentiality and integrity.

AIt ensures reliable and timely access to resources.Correct

Availability in information security means that systems, services, and data must be accessible to authorized users whenever required, without unacceptable delay or disruption. This is typically maintained through redundancy, failover mechanisms, and disaster recovery planning. It is one of the three pillars of the CIA triad alongside Confidentiality and Integrity.

BIt determines actions and behaviors of a single individual within a system.

Tracking or determining the actions and behaviors of an individual within a system describes accountability or non-repudiation, not availability.

CIt ensures that unauthorized modifications are not made to data by authorized personnel or

Preventing unauthorized modifications by authorized personnel describes a nuanced aspect of integrity controls such as least privilege, not availability.

DIt ensures that modifications are not made to data by unauthorized personnel or processes.

Ensuring data is not modified by unauthorized personnel or processes is the definition of integrity, not availability.

Concept tested: CIA triad - availability definition in information security

Source: https://csrc.nist.gov/glossary/term/availability

Topics

#CIA triad#availability#information security management#security concepts

Community Discussion

No community discussion yet for this question.

Full GSEC Practice