Questions and Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Latest Exam Update 2026/2027 | 250
Questions
Questions 1–250
1. Which security principle ensures that information is accessible
only to authorized users?
A) Integrity
B) Confidentiality
C) Availability
D) Authentication
Answer B: Confidentiality
,Rationale: Confidentiality ensures that information is accessible only
to those with proper authorization.
2. A company's database server has been encrypted by
ransomware, and users cannot access their files. Which pillar of the
CIA triad has been primarily violated?
A) Integrity
B) Confidentiality
C) Availability
D) Non-repudiation
Answer C: Availability
Rationale: Availability ensures that systems and data are accessible
when needed; ransomware disrupts access.
3. Which type of control is a security guard at the entrance of a
building?
A) Technical control
B) Physical control
C) Administrative control
,D) Detective control
Answer B: Physical control
Rationale: Physical controls are tangible measures such as guards,
locks, and fences.
4. A security policy that requires employees to use complex
passwords is an example of which type of control?
A) Administrative control
B) Technical control
C) Physical control
D) Compensating control
Answer A: Administrative control
Rationale: Administrative controls are policies, procedures, and
guidelines.
5. Which cryptographic concept ensures that a sender cannot deny
having sent a message?
A) Confidentiality
B) Non-repudiation
, C) Integrity
D) Authorization
Answer B: Non-repudiation
Rationale: Non-repudiation provides proof of origin and delivery,
preventing denial.
6. What is the primary purpose of a change management process in
security?
A) To prevent all changes to the environment
B) To ensure changes are approved, tested, and documented to
minimize risk
C) To reduce the cost of IT operations
D) To speed up the deployment of new features
Answer B: To ensure changes are approved, tested, and
documented to minimize risk
Rationale: Change management reduces the risk of unplanned
disruptions and security issues.
7. Which of the following is an example of a technical control?