SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CC · Domain 1

Security Principles practice questions

Security Principles is worth 24% of the CC exam — the heaviest of the 5 domains. Core cybersecurity concepts, risk management, governance, controls, and professional ethics. Official weighting 24%. 6 fully worked examples are further down this page, answers included.

Exam weight
24%
the heaviest of the 5 domains
Questions
100
across 5 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Security Principles questions, fully explained

Questions from the CC bank mapped to domain 1, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CC practice page.

Question 1Security Principles

An organization encrypts the customer database stored on its file server. Which security principle does this control primarily support?

Choose one.

  • a
    Availability

    Encryption does not keep systems running or data reachable; controls like backups and redundancy support availability.

  • b
    Accounting

    Accounting records what users did, typically through logging; encrypting stored data does not create a record of activity.

  • c
    Confidentiality Correct

    Encryption scrambles data so that anyone without the decryption key cannot read it, which directly protects against unauthorized disclosure.

  • d
    Authorization

    Authorization defines what an authenticated user is permitted to do; encryption protects the readability of data, not permission decisions.

The concept

Security controls map to CIA triad goals. Encryption is the classic confidentiality control because it renders data unreadable to anyone without the correct key.

Why that’s the answer

Encrypting data at rest means that even if the database file is stolen or accessed by an unauthorized person, its contents remain unreadable. That is a protection against unauthorized disclosure, which is confidentiality. It does not keep the server online, log activity, or grant permissions.

How to reason it out
  1. Identify what the control does: encryption makes data unreadable without a key.
  2. Ask which CIA goal is served when unauthorized people cannot read data.
  3. Preventing unauthorized disclosure is confidentiality.
  4. Confirm the distractors map elsewhere: backups map to availability, logs map to accounting, permissions map to authorization.

Exam tip: On the exam, map encryption to confidentiality, hashing to integrity, and backups or redundancy to availability.

CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.

Question 2Security Principles

Which statement best describes integrity as an element of the CIA triad?

Choose one.

  • a
    Information is kept secret from unauthorized viewers

    Keeping information secret from unauthorized viewers describes confidentiality, not integrity.

  • b
    Information remains accurate, complete, and free from unauthorized modification Correct

    Integrity is exactly this: data can be trusted because it has not been altered in an unauthorized or undetected way.

  • c
    Systems and data are reachable by authorized users whenever needed

    Timely, reliable access for authorized users describes availability, not integrity.

  • d
    Users cannot deny actions they have performed on a system

    Being unable to deny an action describes non-repudiation, which is a separate concept from integrity.

The concept

Integrity means information is accurate, complete, and trustworthy, and that any unauthorized change can be prevented or detected.

Why that’s the answer

The defining property of integrity is protection against unauthorized modification. Confidentiality covers secrecy, availability covers access when needed, and non-repudiation covers proof of actions, so only the accuracy-and-no-tampering statement fits.

How to reason it out
  1. Recall the one-line definitions of confidentiality, integrity, and availability.
  2. Integrity focuses on the trustworthiness and accuracy of data over its lifecycle.
  3. Select the statement about accuracy and freedom from unauthorized modification.
  4. Rule out secrecy (confidentiality), uptime (availability), and denial of actions (non-repudiation).

Exam tip: Integrity means data has not been tampered with; if information can be trusted as accurate and unaltered, integrity is intact.

CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.

Question 3Security Principles

After downloading a software installer, an administrator computes its hash value and compares it with the hash published by the vendor. Which security principle is the administrator verifying?

Choose one.

  • a
    Integrity Correct

    A matching hash proves the file was not altered or corrupted in transit, which is a direct verification of integrity.

  • b
    Confidentiality

    Hashing does not hide the file contents; the installer is still fully readable, so no confidentiality is provided.

  • c
    Availability

    Availability concerns whether systems and data are accessible when needed; comparing hashes says nothing about uptime or access.

  • d
    Authorization

    Authorization determines what an authenticated user may do; a hash comparison does not grant or check permissions.

The concept

A hash function produces a fixed-length fingerprint of data. If even one bit of the data changes, the hash changes, which makes hashing the standard tool for detecting unauthorized modification.

Why that’s the answer

Comparing the computed hash with the vendor's published hash tells the administrator whether the file is byte-for-byte identical to the original. A match confirms the file has not been tampered with or corrupted, which is the definition of verifying integrity.

How to reason it out
  1. Identify the mechanism: computing and comparing hash values.
  2. Recall that hashes change whenever the underlying data changes.
  3. A matching hash therefore proves the data is unmodified, which is integrity.
  4. Note that hashing does not encrypt the file, keep it available, or assign permissions.

Exam tip: Hashing detects change: matching hashes mean the data is intact, so hashing maps to integrity on the exam.

CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.

Question 4Security Principles

Which statement best describes privacy in the context of information security?

Choose one.

  • a
    The right of individuals to control how their personal information is collected, used, and shared Correct

    Privacy is centered on the individual's control over their own personal information throughout its lifecycle.

  • b
    The guarantee that systems remain online during a disaster

    Keeping systems online during disruption describes availability and business continuity, not privacy.

  • c
    The process of recording every action a user takes on a network

    Recording user actions describes accounting or auditing; comprehensive monitoring can actually conflict with privacy if done without limits.

  • d
    The technique of scrambling data so only key holders can read it

    Scrambling data describes encryption, a control that can help protect privacy but is not the definition of privacy itself.

The concept

Privacy is the right of individuals to control the collection, use, retention, and sharing of information about themselves. Organizations that handle personal data must respect this right, often under laws and regulations.

Why that’s the answer

The defining idea of privacy is individual control over personal information. Availability, accounting, and encryption are security concepts and controls; they may support or interact with privacy, but none of them defines it.

How to reason it out
  1. Distinguish privacy (a right of individuals over their personal data) from security (the protection mechanisms).
  2. Look for the option centered on individual control of personal information.
  3. Eliminate options describing availability, logging, and encryption, which are security concepts, not the definition of privacy.
  4. Remember that security controls like encryption are often used to help uphold privacy obligations.

Exam tip: Privacy is about an individual's control over their personal information; security provides the controls that help protect that right.

CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.

Question 5Security Principles

A distributed denial-of-service attack floods a company's web server with traffic until legitimate customers can no longer reach the site. Which element of the CIA triad is directly violated?

Choose one.

  • a
    Availability Correct

    Legitimate users are prevented from accessing the service when they need it, which is precisely a loss of availability.

  • b
    Confidentiality

    The attack does not expose any data to unauthorized viewers; no information is disclosed.

  • c
    Integrity

    The attack does not modify or corrupt any data; the website content remains unchanged.

  • d
    Authentication

    Authentication is proving identity; the attack does not defeat or bypass any identity check, it simply overwhelms the server.

The concept

Availability means authorized users have timely and reliable access to systems and data. Denial-of-service attacks are the classic attack against availability.

Why that’s the answer

Flooding a server so legitimate customers cannot reach it denies access to an authorized audience. No data is disclosed and nothing is altered, so confidentiality and integrity are unaffected; the harm is entirely to availability.

How to reason it out
  1. Identify the effect of the attack: legitimate users cannot reach the service.
  2. Map the effect to the CIA triad: blocked access equals lost availability.
  3. Confirm nothing was disclosed (confidentiality intact) and nothing was changed (integrity intact).
  4. Recognize denial-of-service as the standard example of an availability attack.

Exam tip: Denial-of-service attacks target availability; they block legitimate access without necessarily disclosing or altering data.

CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.

Question 6Security Principles

Ransomware encrypts all the files on a hospital's records server, and staff cannot retrieve patient charts until the systems are restored. Which element of the CIA triad does this attack primarily compromise?

Choose one.

  • a
    Authentication

    Authentication verifies identity; the ransomware may have entered through stolen credentials, but the harm described is loss of access to data.

  • b
    Non-repudiation

    Non-repudiation is about proving who performed an action; it is not the security property being denied to hospital staff here.

  • c
    Accounting

    Accounting is the recording of user activity in logs; the scenario describes blocked access to patient data, not a logging failure.

  • d
    Availability Correct

    The core harm is that authorized staff can no longer access the data they need; ransomware is primarily an attack on availability.

The concept

Ransomware makes data unusable by encrypting it and demanding payment for the key. Because authorized users are locked out of their own data, ransomware is taught as an attack on availability.

Why that’s the answer

The scenario's impact is that staff cannot retrieve patient charts, meaning authorized users are denied timely access to data. That is the definition of an availability loss. Some ransomware also steals data, which would add a confidentiality impact, but the primary and described effect is denied access.

How to reason it out
  1. Read the impact stated in the scenario: staff cannot retrieve patient charts.
  2. Denied access for authorized users maps to availability.
  3. Note that ransomware uses encryption as a weapon against the owner rather than as a protective control.
  4. Recall the standard mappings: ransomware and denial-of-service map to availability.

Exam tip: Ransomware locks authorized users out of their own data, making it primarily an availability attack; backups are the key recovery control.

CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts — the lesson that teaches this.

What CC domain 1 tests, topic by topic

The official exam guide breaks Security Principles into 5 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CC practice questions per topic in Security Principles
TopicWhat it coversQuestions
Understand cybersecurity conceptsOfficial CC sub-domain (Security Principles, Sept-2026 outline). Confidentiality, integrity, and availability (the CIA triad); Authentication, Authorization, and Accounting (AAA); non-repudiation; and privacy.20
Understand risk management conceptsOfficial CC sub-domain. The risk management lifecycle and the risk management processes (identification, assessment, treatment, and monitoring).20
Understand governance conceptsOfficial CC sub-domain. Regulations and laws; frameworks and guidelines; and policies, standards (e.g., ISO, Center for Internet Security), and procedures.20
Understand cybersecurity controlsOfficial CC sub-domain. Technical controls, administrative controls, and physical controls, and how they combine to reduce risk.20
Maintain professional and ethical conductOfficial CC sub-domain. Professional code of conduct; due care and due diligence; and the ISC2 Code of Ethics.20
Total100

Revise Security Principles before you drill it

Other CC domains

Security Principles: your questions

Security Principles is domain 1 of the CC exam guide and carries 24% of the scored content — the heaviest of the 5 domains. On a 100-question paper that works out to roughly 24 questions, though ISC2 does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CC exam guide.