nerdexam
CompTIA

SY0-301 · Question #618

The fundamental information security principals include confidentiality, availability and which of the following?

The correct answer is B. The capacity of a system to resist unauthorized changes to stored information. The three foundational principles of information security are the CIA triad - Confidentiality, Integrity, and Availability. Integrity refers to protecting information from unauthorized modification.

General security concepts

Question

The fundamental information security principals include confidentiality, availability and which of the following?

Options

  • AThe ability to secure data against unauthorized disclosure to external sources
  • BThe capacity of a system to resist unauthorized changes to stored information
  • CThe confidence with which a system can attest to the identity of a user
  • DThe characteristic of a system to provide uninterrupted service to authorized users

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    87% (39)
  • C
    2% (1)
  • D
    7% (3)

Why each option

The three foundational principles of information security are the CIA triad - Confidentiality, Integrity, and Availability. Integrity refers to protecting information from unauthorized modification.

AThe ability to secure data against unauthorized disclosure to external sources

Protecting data against unauthorized disclosure describes Confidentiality, the first principle of the CIA triad, not the third.

BThe capacity of a system to resist unauthorized changes to stored informationCorrect

Integrity is the security principle that ensures data and systems are protected from unauthorized creation, modification, or deletion, preserving accuracy and trustworthiness. It is the third pillar of the CIA triad alongside Confidentiality and Availability. Controls such as hashing, digital signatures, access controls, and audit logs are used to enforce and verify integrity.

CThe confidence with which a system can attest to the identity of a user

Attesting to the identity of a user describes Authentication or Non-repudiation, which are security concepts but not the third CIA triad principle.

DThe characteristic of a system to provide uninterrupted service to authorized users

Providing uninterrupted service to authorized users describes Availability, the second principle of the CIA triad, not the third.

Concept tested: CIA triad integrity principle definition

Source: https://www.nist.gov/cybersecurity

Topics

#CIA triad#integrity#information security fundamentals#data protection

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice