Objective Assessment 2026/2027 Actual Exam Complete
Questions and Answers with Detailed Rationales – Pass
Guaranteed – A+ Graded
Section 1: Core Principles & Security Concepts
Q1: During a quarterly audit, a security analyst reviews how a hospital protects patient
records from unauthorized modification. Which pillar of the CIA triad is the analyst
primarily evaluating?
A. Confidentiality, because it prevents data from being viewed by unauthorized
personnel
B. Integrity, which ensures information is not altered in an unauthorized manner
[CORRECT]
C. Availability, since systems must remain online for clinical staff
D. Non-repudiation, which guarantees the sender cannot deny transmitting data
Correct Answer: B
Rationale: The best answer is B. Integrity focuses on maintaining the accuracy and
consistency of data throughout its lifecycle, and protecting records from unauthorized
modification is exactly what this principle addresses. While confidentiality and
availability are important, the specific concern here is alteration rather than disclosure
or uptime.
Q2: A software development team follows the principle that no single person should
have complete control over a critical process from start to finish. Which security
concept does this describe?
A. Least privilege, which limits user permissions to the bare minimum
,B. Separation of duties, designed to prevent fraud and errors by dividing responsibilities
[CORRECT]
C. Need to know, restricting access based on job function requirements
D. Defense in depth, layering multiple security controls together
Correct Answer: B
Rationale: This choice is correct because separation of duties splits critical tasks
among different people so that one individual cannot exploit the entire process, which is
a fundamental internal control in both security and accounting. It goes beyond simple
permission restrictions by addressing workflow design rather than just access rights.
Q3: A network administrator implements firewalls, intrusion detection systems, and
network segmentation to protect a financial database. Which foundational security
model best describes this layered approach?
A. Security through obscurity, which hides system details from potential attackers
B. Defense in depth, utilizing multiple overlapping security controls [CORRECT]
C. Zero trust, which assumes the internal network is already compromised
D. Risk transference, shifting security responsibility to a third party
Correct Answer: B
Rationale: The best answer is B. Defense in depth operates on the premise that no
single control is perfect, so layering firewalls, detection systems, and segmentation
creates redundant protection that can catch threats even if one layer fails. This is a
classic strategy for protecting high-value assets like financial databases.
Q4: A company requires employees to use keycards to enter the building and assigns
parking spots based on job roles. Which category of security controls do these
measures represent?
A. Technical controls, such as encryption and access control lists
B. Physical controls, which protect the organization's facilities and hardware [CORRECT]
C. Administrative controls, including policies and procedures
D. Logical controls that manage digital resource access
Correct Answer: B
Rationale: The best answer is B. Keycard entry systems and parking assignments are
physical security measures meant to restrict and monitor access to tangible facilities,
distinguishing them from technical or administrative controls that operate at the
, software or policy level. Physical controls are often the first line of defense before an
attacker ever reaches a network.
Q5: A database administrator grants a temp worker read-only access to a single table
needed for a report, removing all other permissions. Which principle is being applied?
A. Separation of duties to prevent data manipulation
B. Least privilege, providing only the minimum access necessary to perform a task
[CORRECT]
C. Two-person integrity requiring dual authorization
D. Mandatory access control determined by system labels
Correct Answer: B
Rationale: This choice is correct because least privilege means giving users exactly the
permissions they need—nothing more—to reduce the attack surface if their account is
compromised. Even though separation of duties is related, the scenario specifically
describes limiting the scope of access rather than dividing a task.
Q6: In the context of information security, what is the primary difference between
authentication and authorization?
A. Authentication verifies identity, while authorization determines what resources that
identity can access [CORRECT]
B. Authentication encrypts data in transit, while authorization stores credentials
securely
C. Authentication assigns user roles, while authorization validates passwords
D. There is no practical difference; the terms are interchangeable in most frameworks
Correct Answer: A
Rationale: The best answer is A. Authentication answers the question "Who are you?"
through passwords, biometrics, or tokens, whereas authorization answers "What are you
allowed to do?" by enforcing permissions after identity is confirmed. Confusing these
two is a common source of access control vulnerabilities.
Q7: A security team classifies data as Public, Internal Use Only, Confidential, and
Restricted. Which aspect of security governance does this process represent?
A. Risk assessment calculating annual loss expectancy
B. Data classification, which helps determine appropriate handling and protection
requirements [CORRECT]