ICT 417 CYBERSECURITY PRINCIPLES
FINAL EXAM
Information Security Network Assurance and Vulnerability
Management Questions and Answers Verified Solutions 2026 2027
1. Which core security objective of the CIA Triad ensures that sensitive information is
kept secret from unauthorized users and system processes?
A. Availability
B. Confidentiality
C. Integrity
D. Non-repudiation
Rationale: Confidentiality prevents unauthorized disclosure of data through access controls, encryption,
and classification protocols.
2. What security goal ensures that data remains accurate, complete, and protected
against unauthorized modification or tampering?
A. Accountability
B. Confidentiality
C. Integrity
D. Availability
Rationale: Integrity guarantees that system data has not been modified in transit or at rest, often verified
using cryptographic hash functions.
3. Which attack specifically targets the Availability pillar of the CIA triad by overloading a
network service with traffic?
A. Man-in-the-Middle (MitM) attack
B. Distributed Denial of Service (DDoS) attack
C. SQL Injection (SQLi) attack
D. Phishing attack
Rationale: DDoS flooding consumes system bandwidth or computational resources, rendering
applications inaccessible to legitimate users.
, 4. What fundamental cybersecurity principle dictates that users and applications should
be granted only the minimum permissions necessary to perform their roles?
A. Principle of Least Privilege
B. Defense in Depth
C. Separation of Duties
D. Security through Obscurity
Rationale: The principle of least privilege limits potential security damage by restricting system rights
strictly to required operational duties.
5. What defense strategy employs multiple redundant security layers to protect
organizational assets in case a single control fails?
A. Single Point of Failure design
B. Zero Trust Architecture
C. Defense in Depth
D. Perimeter Security
Rationale: Defense in depth uses overlapping technical, administrative, and physical controls so that
bypassing one layer does not compromise the whole system.
6. Which security concept prevents a sender from denying the authenticity or origination
of a transmitted message?
A. Confidentiality
B. Non-repudiation
C. Authorization
D. Authentication
Rationale: Non-repudiation uses digital signatures and public key infrastructure (PKI) to provide
undeniable proof of message origin and integrity.
7. What security framework operates on the strict motto "Never Trust, Always Verify"
regardless of whether network traffic is internal or external?
A. Bell-LaPadula Model
B. Biba Integrity Model
FINAL EXAM
Information Security Network Assurance and Vulnerability
Management Questions and Answers Verified Solutions 2026 2027
1. Which core security objective of the CIA Triad ensures that sensitive information is
kept secret from unauthorized users and system processes?
A. Availability
B. Confidentiality
C. Integrity
D. Non-repudiation
Rationale: Confidentiality prevents unauthorized disclosure of data through access controls, encryption,
and classification protocols.
2. What security goal ensures that data remains accurate, complete, and protected
against unauthorized modification or tampering?
A. Accountability
B. Confidentiality
C. Integrity
D. Availability
Rationale: Integrity guarantees that system data has not been modified in transit or at rest, often verified
using cryptographic hash functions.
3. Which attack specifically targets the Availability pillar of the CIA triad by overloading a
network service with traffic?
A. Man-in-the-Middle (MitM) attack
B. Distributed Denial of Service (DDoS) attack
C. SQL Injection (SQLi) attack
D. Phishing attack
Rationale: DDoS flooding consumes system bandwidth or computational resources, rendering
applications inaccessible to legitimate users.
, 4. What fundamental cybersecurity principle dictates that users and applications should
be granted only the minimum permissions necessary to perform their roles?
A. Principle of Least Privilege
B. Defense in Depth
C. Separation of Duties
D. Security through Obscurity
Rationale: The principle of least privilege limits potential security damage by restricting system rights
strictly to required operational duties.
5. What defense strategy employs multiple redundant security layers to protect
organizational assets in case a single control fails?
A. Single Point of Failure design
B. Zero Trust Architecture
C. Defense in Depth
D. Perimeter Security
Rationale: Defense in depth uses overlapping technical, administrative, and physical controls so that
bypassing one layer does not compromise the whole system.
6. Which security concept prevents a sender from denying the authenticity or origination
of a transmitted message?
A. Confidentiality
B. Non-repudiation
C. Authorization
D. Authentication
Rationale: Non-repudiation uses digital signatures and public key infrastructure (PKI) to provide
undeniable proof of message origin and integrity.
7. What security framework operates on the strict motto "Never Trust, Always Verify"
regardless of whether network traffic is internal or external?
A. Bell-LaPadula Model
B. Biba Integrity Model