← All CCP Flashcard Decks

CIA Triad & Security Controls Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 CIA Triad & Security Controls flashcards as text
  1. A security policy that prohibits users from installing unauthorized software primarily functions as which type of control?

    Answer: Preventive

    A policy prohibiting unauthorized software is a preventive (administrative) control designed to stop risky actions before they occur.

  2. Which scenario represents a violation of all three CIA Triad properties simultaneously?

    Answer: An attacker encrypts all files and takes the system offline after stealing sensitive data

    Stealing data violates confidentiality, encrypting files violates integrity, and taking the system offline violates availability — hitting all three CIA properties.

  3. Which of the following is primarily a physical security control?

    Answer: Mantrap entry system

    A mantrap is a physical control consisting of two interlocking doors that prevents tailgating and unauthorized physical entry.

  4. An employee is given access to only the specific files needed for their current project. This practice reflects which security principle?

    Answer: Need to know

    The need-to-know principle limits information access to only what is required for a person's specific role or task.

  5. A CCTV system in a server room is used primarily as which type of security control?

    Answer: Detective and deterrent

    CCTV is detective (records activity for review) and deterrent (discourages misconduct when people know they are being recorded).

  6. Which of the following best represents a threat to data confidentiality?

    Answer: An unauthorized user exfiltrating sensitive files

    Exfiltrating sensitive files exposes private data to unauthorized parties, which is a direct confidentiality breach.

  7. In the context of security controls, what is the primary purpose of a deterrent control?

    Answer: To discourage potential attackers from attempting an attack

    Deterrent controls aim to discourage would-be attackers by making an attack seem difficult, risky, or not worthwhile.