{"id":449,"date":"2023-10-23T23:06:10","date_gmt":"2023-10-23T23:06:10","guid":{"rendered":"https:\/\/digisentinel.org\/?p=449"},"modified":"2023-10-24T12:56:47","modified_gmt":"2023-10-24T12:56:47","slug":"security-practice-questions-cia-and-aaa","status":"publish","type":"post","link":"https:\/\/digisentinel.org\/index.php\/2023\/10\/23\/security-practice-questions-cia-and-aaa\/","title":{"rendered":"Security Practice Questions &#8211; CIA and AAA"},"content":{"rendered":"\n<div class=\"wp-block-cover is-light\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-background-dim\"><\/span><img decoding=\"async\" class=\"wp-block-cover__image-background\" alt=\"\" src=\"https:\/\/d3argk3ta83nhz.cloudfront.net\/Images\/padlock-polygonal-wireframe-mesh-looks-dark-blue-background-cyber-security-safe-privacy-other-concept-vector-illustration\/sept_lock_gift_box_2.jpg\" style=\"object-position:49% 81%\" data-object-fit=\"cover\" data-object-position=\"49% 81%\"\/><div class=\"wp-block-cover__inner-container is-layout-flow wp-block-cover-is-layout-flow\">\n<p class=\"has-text-align-center has-x-large-font-size wp-block-paragraph\">Security Practice Questions &#8211; CIA and AAA<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As you delve into this section of the practice tests, prepare to be challenged on your comprehension of the fundamental tenets of information security. Often referred to as the six pillars, these principles\u2014<strong>Confidentiality<\/strong>, <strong>Integrity<\/strong>, <strong>Availability<\/strong>, <strong>Authentication<\/strong>, <strong>Authorization<\/strong>, and <strong>Accounting<\/strong>\u2014form the bedrock of secure information systems. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each question has been crafted to gauge your understanding of how these principles interplay in various scenarios, ensuring that you not only know their definitions but can also apply them in real-world contexts. Dive in, think critically, and solidify your expertise in these essential areas of information security. These Set of questions will test your knowledge of the six pillars of information security. <br><\/p>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>1. Sarah is responsible for managing access to a database. She ensures that users only have the permissions they need to perform their jobs. Which principle is she emphasizing?<\/strong><br>a) Authentication<br>b) Authorization<br>c) Confidentiality<br>d) Accounting<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Authorization<br><em>Explanations:<\/em><br>a) <strong>Authentication:<\/strong> Verifying the identity of a user. Sarah isn&#8217;t verifying their identities; she&#8217;s assigning permissions.<br>b) <strong>Authorization:<\/strong> Determining what a user has access to. This is what Sarah is doing by managing permissions.<br>c) <strong>Confidentiality:<\/strong> Keeping data secret. Sarah isn&#8217;t necessarily keeping the data secret; she&#8217;s managing who has access to what.<br>d) <strong>Accounting:<\/strong> Tracking user activities. The scenario doesn&#8217;t mention Sarah monitoring user actions.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>2. John received an email with a link. The email claims it&#8217;s from his bank, but when he hovers over the link, it directs to a suspicious website. Which principle is potentially being violated?<\/strong><br>a) Authentication<br>b) Integrity<br>c) Availability<br>d) Confidentiality<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Authentication<br><em>Explanations:<\/em><br>a) <strong>Authentication:<\/strong> Ensuring that entities are who they claim to be. The email is not genuinely from the bank, violating this principle.<br>b) <strong>Integrity:<\/strong> Ensures data hasn&#8217;t been altered. The data here (the email) is deceptive but not altered in transit.<br>c) <strong>Availability:<\/strong> Ensuring data is accessible. The email doesn&#8217;t mention data access issues.<br>d) <strong>Confidentiality:<\/strong> Protecting data from unauthorized access. John&#8217;s data hasn&#8217;t been disclosed or accessed in the scenario.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>3. A hospital&#8217;s patient information system goes offline for maintenance during peak hours, causing delays in patient care. Which security principle is directly impacted?<\/strong><br>a) Authorization<br>b) Availability<br>c) Confidentiality<br>d) Accounting<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Availability<br><em>Explanations:<\/em><br>a) <strong>Authorization:<\/strong> This principle isn&#8217;t mentioned as permissions and rights are not the concern.<br>b) <strong>Availability:<\/strong> Ensures systems and data are accessible when needed. The system going offline impacts this principle directly.<br>c) <strong>Confidentiality:<\/strong> There&#8217;s no indication that patient data was exposed.<br>d) <strong>Accounting:<\/strong> The scenario doesn&#8217;t touch on tracking user activities.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>4. During an audit, IT staff cannot determine which users accessed a particular file last month. Which principle is lacking implementation?<\/strong><br>a) Integrity<br>b) Accounting<br>c) Authentication<br>d) Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Accounting<br><em>Explanations:<\/em><br>a) <strong>Integrity:<\/strong> The scenario doesn&#8217;t mention data alteration.<br>b) <strong>Accounting:<\/strong> This deals with tracking user activities. The lack of logs indicates a failure in implementing this principle.<br>c) <strong>Authentication:<\/strong> Identifying users. This isn&#8217;t the focus of the scenario.<br>d) <strong>Authorization:<\/strong> Assigning permissions. The scenario isn&#8217;t about permissions.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>5. A developer insists on having access to the production environment, although his job doesn&#8217;t require it. Granting this access would violate which principle?<\/strong><br>a) Authorization<br>b) Confidentiality<br>c) Authentication<br>d) Non-repudiation<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Authorization<br><em>Explanations:<\/em><br>a) <strong>Authorization:<\/strong> Ensures users have only the permissions they need. Giving the developer access he doesn&#8217;t need violates this.<br>b) <strong>Confidentiality:<\/strong> This could also be impacted if the developer views confidential data, but the main issue here is permissions.<br>c) <strong>Authentication:<\/strong> The scenario doesn&#8217;t involve verifying the developer&#8217;s identity.<br>d) <strong>Non-repudiation:<\/strong> Ensures actions can&#8217;t be denied. This isn&#8217;t the issue in the scenario.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>6. Data is transferred between two systems. To ensure the data remains unchanged during transfer, which principle should be enforced?<\/strong><br>a) Integrity<br>b) Availability<br>c) Authorization<br>d) Confidentiality<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Integrity<br><em>Explanations:<\/em><br>a) <strong>Integrity:<\/strong> Ensures data remains unchanged and trustworthy. This is the principle to uphold when data is transferred between systems. <br>b) <strong>Availability:<\/strong> This relates to system and data access, not data alteration. <br>c) <strong>Authorization:<\/strong> Permissions aren&#8217;t the concern in this scenario. <br>d) <strong>Confidentiality:<\/strong> While important, the focus here is on unchanged data, not keeping it secret.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>7. After a recent breach, a company decides to require two forms of identification before allowing access to its systems. Which principle are they emphasizing?<\/strong><br>a) Authentication<br>b) Accounting<br>c) Authorization<br>d) Availability<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Authentication<br><em>Explanations:<\/em><br>a) <strong>Authentication:<\/strong> Verifying user identity. Requiring two forms of identification strengthens this principle. <br>b) <strong>Accounting:<\/strong> Tracking user actions isn&#8217;t the focus of the scenario. <br>c) <strong>Authorization:<\/strong> The company is trying to confirm user identities, not assign permissions. <br>d) <strong>Availability:<\/strong> The scenario isn&#8217;t about system uptime or data access.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>8. A database administrator sets up a system to log all queries and changes made to a database. What principle is being emphasized?<\/strong><br>a) Confidentiality<br>b) Authorization<br>c) Integrity<br>d) Accounting<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> d) Accounting<br><em>Explanations:<\/em><br>a) <strong>Confidentiality:<\/strong> The scenario isn&#8217;t about keeping data secret. <br>b) <strong>Authorization:<\/strong> Permissions aren&#8217;t the main concern here. <br>c) <strong>Integrity:<\/strong> While ensuring data remains unchanged is important, the scenario focuses on logging activities. <br>d) <strong>Accounting:<\/strong> This is about tracking and logging user actions, which aligns with the scenario.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>9. A company encrypts its sensitive documents to ensure only specific employees can read them. Which principle is this company prioritizing?<\/strong><br>a) Integrity<br>b) Confidentiality<br>c) Availability<br>d) Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Confidentiality<br><em>Explanations:<\/em><br>a) <strong>Integrity:<\/strong> While important, the company&#8217;s focus is on ensuring data secrecy, not ensuring it remains unchanged. <br>b) <strong>Confidentiality:<\/strong> Ensuring data remains hidden from those without the necessary permissions or keys. This is the principle being emphasized. <br>c) <strong>Availability:<\/strong> The scenario doesn&#8217;t touch on data access or system uptime. <br>d) <strong>Authorization:<\/strong> Although permissions are involved, the primary focus is on keeping data secret, not assigning permissions.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>10. IT staff noticed that a user was<\/strong> authorised and <strong>accessed a system but failed to perform multi-factor authentication. To prevent unauthorized access in the future, the company should improve which principle?<\/strong><br>a) Accounting<br>b) Availability<br>c) Authentication<br>d) Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> c) Authentication<br><em>Explanations:<\/em><br>a) <strong>Accounting:<\/strong> This refers to logging user actions, not strengthening access controls. <br>b) <strong>Availability:<\/strong> The scenario doesn&#8217;t relate to system uptime or data access. <br>c) <strong>Authentication:<\/strong> Verifying user identity. The failure in multi-factor authentication shows a need to bolster this principle. <br>d) <strong>Authorization:<\/strong> The concern here is confirming the user&#8217;s identity, not the permissions they have.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>11. A system administrator regularly rotates cryptographic keys and requires longer passphrases for system access. Which two principles are being prioritized?<\/strong><br>a) Confidentiality &amp; Authentication<br>b) Authorization &amp; Integrity<br>c) Availability &amp; Authorization<br>d) Accounting &amp; Authentication<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Confidentiality &amp; Authentication<br><em>Explanations:<\/em><br>a) <strong>Confidentiality &amp; Authentication:<\/strong> Rotating cryptographic keys ensures data remains confidential, and requiring longer passphrases strengthens authentication. <br>b) <strong>Authorization &amp; Integrity:<\/strong> These principles aren&#8217;t directly related to the actions described. <br>c) <strong>Availability &amp; Authorization:<\/strong> The scenario doesn&#8217;t mention system uptime or access permissions. <br>d) <strong>Accounting &amp; Authentication:<\/strong> While authentication is a focus, accounting (tracking\/loging activities) isn&#8217;t mentioned.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>12. After several DDOS attacks, a company decides to distribute its resources to multiple locations to ensure continuous service. Which principle does this action underscore?<\/strong><br>a) Availability<br>b) Confidentiality<br>c) Accounting<br>d) Authentication<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Availability<br><em>Explanations:<\/em><br>a) <strong>Availability:<\/strong> Distributing resources ensures systems remain accessible even under attack. <br>b) <strong>Confidentiality:<\/strong> The scenario doesn&#8217;t discuss keeping data secret.<br> c) <strong>Accounting:<\/strong> The scenario doesn&#8217;t mention tracking user actions. <br>d) <strong>Authentication:<\/strong> The company isn&#8217;t focusing on verifying user identities here.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>13. A finance company ensures that any transaction over $10,000 is logged and alerts the security team. This emphasizes which principle?<\/strong><br>a) Accounting<br>b) Authorization<br>c) Availability<br>d) Integrity<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Accounting<br><em>Explanations:<\/em><br>a) <strong>Accounting:<\/strong> Logging transactions is central to the accounting principle. <br>b) <strong>Authorization:<\/strong> The focus isn&#8217;t on user permissions. <br>c) <strong>Availability:<\/strong> The scenario doesn&#8217;t relate to system uptime or data access. <br>d) <strong>Integrity:<\/strong> Data alteration isn&#8217;t the scenario&#8217;s concern.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>14. To ensure that a file hasn&#8217;t been tampered with during transfer, a company uses a method to compare the file&#8217;s value before and after the transfer. What is this method called?<\/strong><br>a) Authorization Check<br>b) Encryption<br>c) Multi-factor Authentication<br>d) Hashing<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> d) Hashing<br><em>Explanations:<\/em><br>a) <strong>Authorization Check:<\/strong> This pertains to user permissions, not data integrity. <br>b) <strong>Encryption:<\/strong> While it secures data, it doesn&#8217;t specifically ensure data remains unchanged. <br>c) <strong>Multi-factor Authentication:<\/strong> This verifies user identity, not data integrity. <br>d) <strong>Hashing:<\/strong> This creates a unique value for data. By comparing hashes before and after transfer, integrity can be verified.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>15. Users complain they cannot access a shared document because another person is editing it. This issue affects which security principle?<\/strong><br>a) Confidentiality<br>b) Authentication<br>c) Availability<br>d) Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> c) Availability<br><em>Explanations:<\/em><br>a) <strong>Confidentiality:<\/strong> The scenario isn&#8217;t about keeping data secret. <br>b) <strong>Authentication:<\/strong> The scenario doesn&#8217;t touch on verifying user identities. <br>c) <strong>Availability:<\/strong> This principle ensures that resources are available when needed. The document being locked affects its availability. <br>d) <strong>Authorization:<\/strong> The problem isn&#8217;t about user permissions.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>16. An organization implements a system where employees can only access the server room using a combination of a key card and fingerprint scan. This is an example of?<\/strong><br>a) Single-factor Authentication<br>b) Dual-factor Authentication<br>c) Multi-level Authorization<br>d) Biometric Accounting<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Dual-factor Authentication<br><em>Explanations:<\/em><br>a) <strong>Single-factor Authentication:<\/strong> Only one method of verification is used, whereas the scenario mentions two. <br>b) <strong>Dual-factor Authentication:<\/strong> Using two methods (key card and fingerprint) emphasizes this principle. <br>c) <strong>Multi-level Authorization:<\/strong> This isn&#8217;t a standard term, and the scenario is about authentication, not permissions. <br>d) <strong>Biometric Accounting:<\/strong> While biometrics are used, accounting (tracking activities) isn&#8217;t the focus here.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>17. A company&#8217;s system keeps track of failed login attempts and automatically locks accounts after three failures. Which principles are being emphasized?<\/strong><br>a) Authentication &amp; Accounting<br>b) Availability &amp; Authorization<br>c) Integrity &amp; Availability<br>d) Authorization &amp; Integrity<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Authentication &amp; Accounting<br><em>Explanations:<\/em><br>a) <strong>Authentication &amp; Accounting:<\/strong> Verifying user identities (by monitoring login attempts) and tracking user actions are the focuses. <br>b) <strong>Availability &amp; Authorization:<\/strong> The scenario doesn&#8217;t discuss system uptime or user permissions. <br>c) <strong>Integrity &amp; Availability:<\/strong> Data alteration and system uptime aren&#8217;t the main concerns. <br>d) <strong>Authorization &amp; Integrity:<\/strong> The scenario isn&#8217;t centered on permissions or ensuring data remains unchanged.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>18. Before accessing sensitive data, a user must provide a password, a smart card, and a retinal scan. This is an example of?<\/strong><br>a) Triple-factor Authentication<br>b) Multi-factor Authorization<br>c) Biometric Encryption<br>d) Triple-level Integrity<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Triple-factor Authentication<br><em>Explanations:<\/em><br>a) <strong>Triple-factor Authentication:<\/strong> Using three methods to verify identity emphasizes this principle. <br>b) <strong>Multi-factor Authorization:<\/strong> The scenario focuses on authentication (verifying identity) not permissions. <br>c) <strong>Biometric Encryption:<\/strong> While biometrics are used, encryption isn&#8217;t the primary focus. <br>d) <strong>Triple-level Integrity:<\/strong> This isn&#8217;t a standard term and doesn&#8217;t relate to the scenario.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>19. During an audit, a company discovers unauthorized access but struggles to ascertain which employee accessed the system. This situation highlights a deficiency in which principle?<\/strong><br>a) Integrity<br>b) Authentication<br>c) Availability<br>d) Accounting<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> d) Accounting<br><em>Explanations:<\/em><br>a) <strong>Integrity:<\/strong> Data alteration isn&#8217;t the primary concern. <br>b) <strong>Authentication:<\/strong> The issue isn&#8217;t about verifying user identity but tracking actions. <br>c) <strong>Availability:<\/strong> The scenario doesn&#8217;t mention system uptime or access problems. <br>d) <strong>Accounting:<\/strong> A lack of logs or tracking emphasizes a shortfall in this principle.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>20. An IT department implements a digital signature to ensure the source and content of a message remain unchanged during transmission. Which principles are being prioritized?<\/strong><br>a) Confidentiality &amp; Integrity<br>b) Authorization &amp; Authentication<br>c) Accounting &amp; Availability<br>d) Authentication &amp; Integrity<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> d) Authentication &amp; Integrity<br><em>Explanations:<\/em><br>a) <strong>Confidentiality &amp; Integrity:<\/strong> While ensuring data remains unchanged is a focus, the scenario doesn&#8217;t emphasize keeping data secret. <br>b) <strong>Authorization &amp; Authentication:<\/strong> Verifying the source of a message (authentication) is one focus, but permissions (authorization) aren&#8217;t. <br>c) <strong>Accounting &amp; Availability:<\/strong> The scenario doesn&#8217;t touch on tracking user actions or system uptime. <br>d) <strong>Authentication &amp; Integrity:<\/strong> Verifying the message&#8217;s source and ensuring its content remains unchanged are the main focuses.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>21. A user can view and edit a document but cannot delete it. This scenario is governed by which principle?<\/strong><br>a) Availability<br>b) Authentication<br>c) Authorization<br>d) Integrity<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> c) Authorization<br><em>Explanations:<\/em><br>a) <strong>Availability:<\/strong> The scenario doesn&#8217;t relate to system uptime or access problems. <br>b) <strong>Authentication:<\/strong> The issue isn&#8217;t about verifying user identity. <br>c) <strong>Authorization:<\/strong> Permissions, like viewing, editing, and deleting, fall under this principle. <br>d) <strong>Integrity:<\/strong> The scenario doesn&#8217;t focus on ensuring data remains unchanged.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>22. To ensure employees don&#8217;t unintentionally modify data, a company makes regular backups and checks data consistency using algorithms. Which principle is being prioritized?<\/strong><br>a) Confidentiality<br>b) Integrity<br>c) Authorization<br>d) Authentication<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Integrity<br><em>Explanations:<\/em><br>a) <strong>Confidentiality:<\/strong> The actions taken aren&#8217;t about keeping data secret. <br>b) <strong>Integrity:<\/strong> Regular backups and consistency checks ensure data remains unchanged, emphasizing this principle. <br>c) <strong>Authorization:<\/strong> The scenario doesn&#8217;t center on user permissions. <br>d) <strong>Authentication:<\/strong> The actions don&#8217;t relate to verifying user identities.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>23. A system requires users to change their passwords every 30 days. This practice emphasizes which principle?<\/strong><br>a) Confidentiality<br>b) Integrity<br>c) Authentication<br>d) Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> c) Authentication<br><em>Explanations:<\/em><br>a) <strong>Confidentiality:<\/strong> The focus isn&#8217;t on keeping data secret. <br>b) <strong>Integrity:<\/strong> The scenario isn&#8217;t about ensuring data remains unchanged. <br>c) <strong>Authentication:<\/strong> Regular password changes strengthen user identity verification. <br>d) <strong>Authorization:<\/strong> The focus isn&#8217;t on user permissions.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>24. To monitor resource usage and identify potential breaches, an organization keeps detailed logs of user activity and analyzes them regularly. This emphasizes which principle?<\/strong><br>a) Authorization<br>b) Authentication<br>c) Accounting<br>d) Availability<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> c) Accounting<br><em>Explanations:<\/em><br>a) <strong>Authorization:<\/strong> User permissions aren&#8217;t the scenario&#8217;s focus. <br>b) <strong>Authentication:<\/strong> The actions don&#8217;t center on verifying user identities. <br>c) <strong>Accounting:<\/strong> Keeping and analyzing detailed logs falls squarely under this principle. <br>d) <strong>Availability:<\/strong> The scenario doesn&#8217;t touch on system uptime or access problems.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>25. A company restricts access to its main server by using biometric measures, ensuring only authorized personnel can enter. This underscores which principle?<\/strong><br>a) Authentication<br>b) Authorization<br>c) Availability<br>d) Integrity<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Authorization<br><em>Explanations:<\/em><br>a) <strong>Authentication:<\/strong> While biometric measures verify identity, the focus is on who has access. <br>b) <strong>Authorization:<\/strong> Restricting server room access based on permissions emphasizes this principle. <br>c) <strong>Availability:<\/strong> The scenario doesn&#8217;t discuss system uptime. <br>d) <strong>Integrity:<\/strong> The scenario doesn&#8217;t focus on ensuring data remains unchanged.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>26. Before sending sensitive information, a company encrypts the data, ensuring only the intended recipient can decrypt it. This practice underscores which principle?<\/strong><br>a) Integrity<br>b) Confidentiality<br>c) Authentication<br>d) Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Confidentiality<br><em>Explanations:<\/em><br>a) <strong>Integrity:<\/strong> The scenario isn&#8217;t about ensuring data remains unchanged. <br>b) <strong>Confidentiality:<\/strong> Encrypting data to ensure only certain individuals can access it emphasizes this principle. <br>c) <strong>Authentication:<\/strong> The actions don&#8217;t center on verifying user identities. <br>d) <strong>Authorization:<\/strong> The scenario doesn&#8217;t discuss user permissions in depth.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>27. An application checks user permissions before granting access to certain modules, ensuring only those with the right permissions can use them. This process demonstrates which principle?<\/strong><br>a) Authentication<br>b) Authorization<br>c) Accounting<br>d) Confidentiality<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> b) Authorization<br><em>Explanations:<\/em><br>a) <strong>Authentication:<\/strong> The application isn&#8217;t primarily verifying user identity. <br>b) <strong>Authorization:<\/strong> Checking permissions before granting access to modules underscores this principle. <br>c) <strong>Accounting:<\/strong> The scenario doesn&#8217;t discuss tracking user actions. <br>d) <strong>Confidentiality:<\/strong> While there&#8217;s an element of keeping data from unauthorized users, the main focus is on permissions.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>28. A company uses a combination of username\/password and hardware token for access to a secure system. This combination aims to improve which security principle?<\/strong><br>a) Authentication<br>b) Authorization<br>c) Accounting<br>d) Availability<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Authentication<br><em>Explanations:<\/em><br>a) <strong>Authentication:<\/strong> Using multiple methods to verify identity emphasizes this principle. <br>b) <strong>Authorization:<\/strong> The scenario doesn&#8217;t focus on user permissions. <br>c) <strong>Accounting:<\/strong> The actions taken aren&#8217;t about tracking user activities. <br>d) <strong>Availability:<\/strong> The scenario doesn&#8217;t relate to system uptime or access.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>29. A system where employees clock in and out using a biometric fingerprint scanner aims to ensure the accuracy and reliability of attendance data. This scenario prioritizes which principle?<\/strong><br>a) Integrity<br>b) Authentication<br>c) Authorization<br>d) Availability<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Integrity<br><em>Explanations:<\/em><br>a) <strong>Integrity:<\/strong> Ensuring the accuracy and reliability of data emphasizes this principle. <br>b) <strong>Authentication:<\/strong> While the system verifies identity, its main purpose is to ensure data accuracy. <br>c) <strong>Authorization:<\/strong> The scenario isn&#8217;t centered on user permissions. <br>d) <strong>Availability:<\/strong> The system&#8217;s uptime or access isn&#8217;t the main focus.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>30. After noticing a spike in resource use, an IT team traces the anomaly to a specific user. However, further investigation reveals that the user&#8217;s credentials were stolen. This breach affected which security principles?<\/strong><br>a) Authentication &amp; Authorization<br>b) Availability &amp; Integrity<br>c) Accounting &amp; Authentication<br>d) Confidentiality &amp; Authorization<\/summary>\n<p class=\"wp-block-paragraph\"><strong>Answer:<\/strong> a) Authentication &amp; Authorization<br><em>Explanations:<\/em><br>a) <strong>Authentication &amp; Authorization:<\/strong> Stolen credentials directly compromise the verification of identity and potentially grant unauthorized permissions. <br>b) <strong>Availability &amp; Integrity:<\/strong> While resource use was affected, the main breach was unauthorized access. <br>c) <strong>Accounting &amp; Authentication:<\/strong> The focus isn&#8217;t on tracking user actions. <br>d) <strong>Confidentiality &amp; Authorization:<\/strong> While unauthorized access was granted, the data&#8217;s secrecy wasn&#8217;t the primary concern.<\/p>\n<\/details>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"has-text-align-right wp-block-paragraph\">Cover Image by <a rel=\"noreferrer noopener\" href=\"https:\/\/www.freepik.com\/free-vector\/padlock-polygonal-wireframe-mesh-looks-dark-blue-background-cyber-security-safe-privacy-other-concept-vector-illustration_24058557.htm#page=2&amp;query=Cyber%20Security%20Pyramid&amp;position=30&amp;from_view=search&amp;track=ais\" target=\"_blank\">WangXiNa<\/a> on Freepik<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As you delve into this section of the practice tests, prepare to be challenged on your comprehension of the fundamental tenets of information security. Often referred to as the six pillars, these principles\u2014Confidentiality, Integrity, Availability, Authentication, Authorization, and Accounting\u2014form the bedrock of secure information systems. Each question has been crafted to gauge your understanding of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false},"categories":[41],"tags":[47,53,51,52,50,46,48,35,49],"class_list":["post-449","post","type-post","status-publish","format-standard","hentry","category-practice-tests","tag-aaa-security","tag-accounting","tag-authentication","tag-authorization","tag-availability","tag-cia-traid","tag-confidentiality","tag-cyber-security-practice-tests","tag-integrity"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pgs2Ve-7f","_links":{"self":[{"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/posts\/449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/comments?post=449"}],"version-history":[{"count":9,"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/posts\/449\/revisions"}],"predecessor-version":[{"id":460,"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/posts\/449\/revisions\/460"}],"wp:attachment":[{"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/media?parent=449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/categories?post=449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digisentinel.org\/index.php\/wp-json\/wp\/v2\/tags?post=449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}