Cybersecurity Fundamentals Exam
Questions And Correct Answers
(Verified Answers) Plus Rationales
2026 Q&A | Instant Download Pdf
1. Which of the following best describes the primary goal of
cybersecurity?
A. Increasing computer processing speed
B. Protecting information systems, networks, and data from
unauthorized access and harm
C. Eliminating the need for software updates
D. Replacing all human decision-making
Answer: B. Protecting information systems, networks, and data from
unauthorized access and harm
Rationale: Cybersecurity focuses on protecting systems, networks,
applications, devices, and information from threats such as
unauthorized access, disruption, alteration, destruction, and theft.
2. Which three principles form the traditional CIA triad of
information security?
A. Control, Inspection, Authentication
B. Confidentiality, Integrity, Availability
C. Certification, Identification, Authorization
D. Compliance, Intelligence, Assessment
Answer: B. Confidentiality, Integrity, Availability
,Rationale: The CIA triad represents three fundamental security
objectives. Confidentiality prevents unauthorized disclosure, integrity
protects information from improper modification, and availability
ensures authorized users can access resources when needed.
3. What does confidentiality mean in cybersecurity?
A. Ensuring systems never experience downtime
B. Ensuring data cannot be modified
C. Ensuring information is accessible only to authorized individuals
or systems
D. Ensuring every file has a backup
Answer: C. Ensuring information is accessible only to authorized
individuals or systems
Rationale: Confidentiality protects sensitive information against
unauthorized disclosure. Access controls, encryption, authentication,
and data classification are commonly used to support confidentiality.
4. What security property ensures that data has not been improperly
changed?
A. Availability
B. Confidentiality
C. Integrity
D. Scalability
Answer: C. Integrity
Rationale: Integrity means information remains accurate, complete,
and trustworthy and is not altered without authorization. Hashing,
digital signatures, access controls, and audit mechanisms can help
protect integrity.
, 5. Which security objective ensures that authorized users can access
systems and information when required?
A. Confidentiality
B. Integrity
C. Availability
D. Nonrepudiation
Answer: C. Availability
Rationale: Availability means systems, services, applications, and
information remain accessible to authorized users when needed.
Redundancy, backups, failover systems, capacity planning, and denial-
of-service protection can improve availability.
6. What is a threat?
A. A completed security audit
B. A security control that prevents attacks
C. A potential cause of harm to an information system or
organization
D. A software license
Answer: C. A potential cause of harm to an information system or
organization
Rationale: A threat is a potential source of an unwanted security event.
Threats may come from malicious actors, technical failures, natural
disasters, human mistakes, or other circumstances.
7. What is a vulnerability?
A. A confirmed data breach
B. A security policy
C. A weakness that could be exploited to compromise a system or
, asset
D. A type of encryption algorithm
Answer: C. A weakness that could be exploited to compromise a system
or asset
Rationale: A vulnerability is a weakness in software, hardware,
configuration, processes, or human behavior that may be exploited by
a threat. Vulnerability management attempts to identify and reduce
such weaknesses.
8. What is risk in cybersecurity generally concerned with?
A. Only the cost of computer hardware
B. The potential for a threat to exploit a vulnerability and cause
harm
C. The number of employees in an organization
D. The age of an operating system
Answer: B. The potential for a threat to exploit a vulnerability and
cause harm
Rationale: Cybersecurity risk reflects the possibility and potential
impact of adverse events. Risk is commonly evaluated by considering
threats, vulnerabilities, likelihood, and consequences.
9. Which term describes a person who uses computer systems to
perform malicious activities?
A. Auditor
B. Administrator
C. Threat actor
D. End user
Answer: C. Threat actor
Questions And Correct Answers
(Verified Answers) Plus Rationales
2026 Q&A | Instant Download Pdf
1. Which of the following best describes the primary goal of
cybersecurity?
A. Increasing computer processing speed
B. Protecting information systems, networks, and data from
unauthorized access and harm
C. Eliminating the need for software updates
D. Replacing all human decision-making
Answer: B. Protecting information systems, networks, and data from
unauthorized access and harm
Rationale: Cybersecurity focuses on protecting systems, networks,
applications, devices, and information from threats such as
unauthorized access, disruption, alteration, destruction, and theft.
2. Which three principles form the traditional CIA triad of
information security?
A. Control, Inspection, Authentication
B. Confidentiality, Integrity, Availability
C. Certification, Identification, Authorization
D. Compliance, Intelligence, Assessment
Answer: B. Confidentiality, Integrity, Availability
,Rationale: The CIA triad represents three fundamental security
objectives. Confidentiality prevents unauthorized disclosure, integrity
protects information from improper modification, and availability
ensures authorized users can access resources when needed.
3. What does confidentiality mean in cybersecurity?
A. Ensuring systems never experience downtime
B. Ensuring data cannot be modified
C. Ensuring information is accessible only to authorized individuals
or systems
D. Ensuring every file has a backup
Answer: C. Ensuring information is accessible only to authorized
individuals or systems
Rationale: Confidentiality protects sensitive information against
unauthorized disclosure. Access controls, encryption, authentication,
and data classification are commonly used to support confidentiality.
4. What security property ensures that data has not been improperly
changed?
A. Availability
B. Confidentiality
C. Integrity
D. Scalability
Answer: C. Integrity
Rationale: Integrity means information remains accurate, complete,
and trustworthy and is not altered without authorization. Hashing,
digital signatures, access controls, and audit mechanisms can help
protect integrity.
, 5. Which security objective ensures that authorized users can access
systems and information when required?
A. Confidentiality
B. Integrity
C. Availability
D. Nonrepudiation
Answer: C. Availability
Rationale: Availability means systems, services, applications, and
information remain accessible to authorized users when needed.
Redundancy, backups, failover systems, capacity planning, and denial-
of-service protection can improve availability.
6. What is a threat?
A. A completed security audit
B. A security control that prevents attacks
C. A potential cause of harm to an information system or
organization
D. A software license
Answer: C. A potential cause of harm to an information system or
organization
Rationale: A threat is a potential source of an unwanted security event.
Threats may come from malicious actors, technical failures, natural
disasters, human mistakes, or other circumstances.
7. What is a vulnerability?
A. A confirmed data breach
B. A security policy
C. A weakness that could be exploited to compromise a system or
, asset
D. A type of encryption algorithm
Answer: C. A weakness that could be exploited to compromise a system
or asset
Rationale: A vulnerability is a weakness in software, hardware,
configuration, processes, or human behavior that may be exploited by
a threat. Vulnerability management attempts to identify and reduce
such weaknesses.
8. What is risk in cybersecurity generally concerned with?
A. Only the cost of computer hardware
B. The potential for a threat to exploit a vulnerability and cause
harm
C. The number of employees in an organization
D. The age of an operating system
Answer: B. The potential for a threat to exploit a vulnerability and
cause harm
Rationale: Cybersecurity risk reflects the possibility and potential
impact of adverse events. Risk is commonly evaluated by considering
threats, vulnerabilities, likelihood, and consequences.
9. Which term describes a person who uses computer systems to
perform malicious activities?
A. Auditor
B. Administrator
C. Threat actor
D. End user
Answer: C. Threat actor