Security Fundamentals Professional Certification (SFPC) Exam
Questions and Answers Latest
QUESTION 1
Which of the following best defines the concept of confidentiality in information security?
A. Ensuring data is accurate and complete
B. Guaranteeing that only authorized individuals can access data
C. Providing resources to users whenever needed
D. Ensuring systems remain operational during disruptions
CORRECT ANSWER: B
RATIONALE: Confidentiality means limiting information access to authorized individuals only.
Option A refers to integrity, option C relates to availability, and option D concerns continuity.
QUESTION 2
In the CIA triad, which element is primarily concerned with preventing unauthorized data
alteration?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
CORRECT ANSWER: B
RATIONALE: Integrity ensures that information remains accurate and unaltered. Confidentiality
prevents unauthorized access, and availability guarantees system uptime.
QUESTION 3
A strong password policy primarily enhances which aspect of security?
A. Availability
B. Authentication
C. Non-repudiation
D. Integrity
,CORRECT ANSWER: B
RATIONALE: Strong passwords verify user identity (authentication). They indirectly protect
confidentiality and integrity but are primarily an authentication control.
QUESTION 4
What is the most appropriate classification for information that could cause serious damage to
national security if disclosed?
A. Controlled Unclassified Information (CUI)
B. Confidential
C. Secret
D. Top Secret
CORRECT ANSWER: C
RATIONALE: Information classified as “Secret” would cause serious damage if disclosed. “Top
Secret” would cause exceptionally grave damage, while “Confidential” indicates potential
damage.
QUESTION 5
Which of the following best describes access control?
A. A mechanism to ensure no unauthorized person modifies data
B. A method of assigning user rights and privileges
C. A form of encryption
D. A software testing technique
CORRECT ANSWER: B
RATIONALE: Access control defines who can access which resources and under what conditions.
Encryption protects data, but access control manages permissions.
QUESTION 6
The principle of least privilege requires that:
A. Users are denied all access by default
B. Users receive only the permissions necessary to perform their duties
C. Every account must have administrator rights
D. Access is unrestricted across departments
,CORRECT ANSWER: B
RATIONALE: Least privilege minimizes risk by limiting user access to essential resources only.
QUESTION 7
Which of the following is most directly associated with availability in cybersecurity?
A. Firewalls
B. Redundant power supply
C. Data encryption
D. Password policies
CORRECT ANSWER: B
RATIONALE: Availability focuses on ensuring system uptime and resource accessibility;
redundancy supports that goal.
QUESTION 8
Which of these is an example of a technical control?
A. Security policy
B. Security awareness training
C. Encryption
D. Disciplinary measures
CORRECT ANSWER: C
RATIONALE: Technical controls involve hardware or software mechanisms, such as encryption or
firewalls, rather than administrative or operational procedures.
QUESTION 9
A security incident can best be defined as:
A. A system functioning normally
B. Any event that violates or threatens information security
C. Scheduled maintenance of systems
D. A routine user log-in attempt
CORRECT ANSWER: B
RATIONALE: A security incident is an event that compromises data confidentiality, integrity, or
availability.
, QUESTION 10
In a risk management process, the likelihood of a threat indicates:
A. The monetary value of assets at risk
B. How severe the consequences of an incident would be
C. The probability that a particular threat will occur
D. The ease of system recovery after a breach
CORRECT ANSWER: C
RATIONALE: Likelihood measures the probability that a threat will exploit a vulnerability.
QUESTION 11
Which of the following is an administrative control?
A. Firewall configuration
B. Security training programs
C. Antivirus software
D. Network segmentation
CORRECT ANSWER: B
RATIONALE: Administrative controls include policies, procedures, and training initiatives guiding
personnel behavior.
QUESTION 12
Which regulation governs the protection of health information in the United States?
A. GDPR
B. FISMA
C. HIPAA
D. FERPA
CORRECT ANSWER: C
RATIONALE: The Health Insurance Portability and Accountability Act (HIPAA) establishes privacy
and security standards for medical information.
QUESTION 13
Questions and Answers Latest
QUESTION 1
Which of the following best defines the concept of confidentiality in information security?
A. Ensuring data is accurate and complete
B. Guaranteeing that only authorized individuals can access data
C. Providing resources to users whenever needed
D. Ensuring systems remain operational during disruptions
CORRECT ANSWER: B
RATIONALE: Confidentiality means limiting information access to authorized individuals only.
Option A refers to integrity, option C relates to availability, and option D concerns continuity.
QUESTION 2
In the CIA triad, which element is primarily concerned with preventing unauthorized data
alteration?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
CORRECT ANSWER: B
RATIONALE: Integrity ensures that information remains accurate and unaltered. Confidentiality
prevents unauthorized access, and availability guarantees system uptime.
QUESTION 3
A strong password policy primarily enhances which aspect of security?
A. Availability
B. Authentication
C. Non-repudiation
D. Integrity
,CORRECT ANSWER: B
RATIONALE: Strong passwords verify user identity (authentication). They indirectly protect
confidentiality and integrity but are primarily an authentication control.
QUESTION 4
What is the most appropriate classification for information that could cause serious damage to
national security if disclosed?
A. Controlled Unclassified Information (CUI)
B. Confidential
C. Secret
D. Top Secret
CORRECT ANSWER: C
RATIONALE: Information classified as “Secret” would cause serious damage if disclosed. “Top
Secret” would cause exceptionally grave damage, while “Confidential” indicates potential
damage.
QUESTION 5
Which of the following best describes access control?
A. A mechanism to ensure no unauthorized person modifies data
B. A method of assigning user rights and privileges
C. A form of encryption
D. A software testing technique
CORRECT ANSWER: B
RATIONALE: Access control defines who can access which resources and under what conditions.
Encryption protects data, but access control manages permissions.
QUESTION 6
The principle of least privilege requires that:
A. Users are denied all access by default
B. Users receive only the permissions necessary to perform their duties
C. Every account must have administrator rights
D. Access is unrestricted across departments
,CORRECT ANSWER: B
RATIONALE: Least privilege minimizes risk by limiting user access to essential resources only.
QUESTION 7
Which of the following is most directly associated with availability in cybersecurity?
A. Firewalls
B. Redundant power supply
C. Data encryption
D. Password policies
CORRECT ANSWER: B
RATIONALE: Availability focuses on ensuring system uptime and resource accessibility;
redundancy supports that goal.
QUESTION 8
Which of these is an example of a technical control?
A. Security policy
B. Security awareness training
C. Encryption
D. Disciplinary measures
CORRECT ANSWER: C
RATIONALE: Technical controls involve hardware or software mechanisms, such as encryption or
firewalls, rather than administrative or operational procedures.
QUESTION 9
A security incident can best be defined as:
A. A system functioning normally
B. Any event that violates or threatens information security
C. Scheduled maintenance of systems
D. A routine user log-in attempt
CORRECT ANSWER: B
RATIONALE: A security incident is an event that compromises data confidentiality, integrity, or
availability.
, QUESTION 10
In a risk management process, the likelihood of a threat indicates:
A. The monetary value of assets at risk
B. How severe the consequences of an incident would be
C. The probability that a particular threat will occur
D. The ease of system recovery after a breach
CORRECT ANSWER: C
RATIONALE: Likelihood measures the probability that a threat will exploit a vulnerability.
QUESTION 11
Which of the following is an administrative control?
A. Firewall configuration
B. Security training programs
C. Antivirus software
D. Network segmentation
CORRECT ANSWER: B
RATIONALE: Administrative controls include policies, procedures, and training initiatives guiding
personnel behavior.
QUESTION 12
Which regulation governs the protection of health information in the United States?
A. GDPR
B. FISMA
C. HIPAA
D. FERPA
CORRECT ANSWER: C
RATIONALE: The Health Insurance Portability and Accountability Act (HIPAA) establishes privacy
and security standards for medical information.
QUESTION 13