SSCP · Question #45
Controlling access to information systems and associated networks is necessary for the preservation of their:
The correct answer is B. Confidentiality, integrity, and availability. Option B is correct because access control in information security is designed to protect the CIA triad - Confidentiality (preventing unauthorized disclosure), Integrity (preventing unauthorized modification), and Availability (ensuring authorized users can access resources)…
Question
Options
- AAuthenticity, confidentiality and availability
- BConfidentiality, integrity, and availability.
- Cintegrity and availability.
- Dauthenticity,confidentiality, integrity and availability.
How the community answered
(18 responses)- A6% (1)
- B89% (16)
- D6% (1)
Explanation
Option B is correct because access control in information security is designed to protect the CIA triad - Confidentiality (preventing unauthorized disclosure), Integrity (preventing unauthorized modification), and Availability (ensuring authorized users can access resources) - which is the universally accepted framework for information security goals.
Why the distractors fail:
- A replaces "integrity" with "authenticity," which is not part of the classic CIA triad and omits a core pillar.
- C omits confidentiality entirely, which is arguably the most fundamental reason access control exists.
- D adds "authenticity" on top of the correct triad - authenticity is a related but separate concept (sometimes addressed under non-repudiation), and this answer is simply an expansion beyond the accepted framework.
Memory tip: Use the acronym CIA - think of access control as a security clearance system, just like a CIA agent needs the right clearance (Confidentiality), files can't be tampered with (Integrity), and agents must be able to reach what they need (Availability).
Topics
Community Discussion
No community discussion yet for this question.