CSIA Final Exam Version 1 – 100
Comprehensive Practice Questions &
Answers | Detailed Rationales | Exam-
Focused Study Guide |Instant
Downloaded PDF
SECTION 1: INFORMATION SECURITY
FUNDAMENTALS
Questions 1–10
1. Which three principles form the CIA triad?
A. Confidentiality, Integrity, Availability
B. Control, Identification, Authentication
C. Confidentiality, Identification, Authorization
D. Control, Integrity, Authentication
Answer: A — Confidentiality, Integrity, Availability
Rationale: The CIA triad is the fundamental model of information security. Confidentiality
prevents unauthorized disclosure, integrity protects information from unauthorized alteration,
and availability ensures authorized users can access information when needed.
2. Which security principle ensures that information is accessible when
required?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: C — Availability
Rationale: Availability ensures systems, applications, and information remain accessible to
authorized users when required.
,3. Which control primarily prevents unauthorized disclosure of information?
A. Confidentiality
B. Availability
C. Redundancy
D. Non-repudiation
Answer: A — Confidentiality
Rationale: Confidentiality protects sensitive information from being accessed or disclosed by
unauthorized individuals.
4. What is the primary purpose of authentication?
A. Determine what a user can access
B. Verify the identity of a user
C. Encrypt user information
D. Monitor network traffic
Answer: B — Verify the identity of a user
Rationale: Authentication establishes that a person or system is who or what it claims to be.
Authorization determines what that authenticated entity is allowed to do.
5. Which process determines what resources an authenticated user may
access?
A. Authentication
B. Authorization
C. Identification
D. Accounting
Answer: B — Authorization
Rationale: Authorization occurs after authentication and determines permissions and access
rights.
6. Which of the following is an example of something you know?
A. Fingerprint
B. Smart card
,C. Password
D. Security token
Answer: C — Password
Rationale: Authentication factors are commonly categorized as something you know, have,
or are. A password is something you know.
7. What is non-repudiation intended to provide?
A. Proof that an action or transaction occurred and cannot easily be denied
B. Faster network performance
C. Protection against malware
D. Physical protection of servers
Answer: A — Proof that an action or transaction occurred and cannot easily be denied
Rationale: Non-repudiation provides evidence linking an action or transaction to its
originator, commonly through mechanisms such as digital signatures and audit records.
8. Which security concept involves limiting users to only the access necessary
for their jobs?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Open access
Answer: B — Least privilege
Rationale: Least privilege gives users, applications, and processes only the permissions
necessary to perform their authorized tasks.
9. What is defense in depth?
A. Using one extremely strong security control
B. Eliminating all security controls except firewalls
C. Using multiple layers of security controls
D. Allowing unrestricted access
Answer: C — Using multiple layers of security controls
, Rationale: Defense in depth assumes that individual controls can fail and therefore uses
multiple complementary layers of protection.
10. Which security objective is primarily concerned with preventing
unauthorized modification?
A. Availability
B. Integrity
C. Confidentiality
D. Authentication
Answer: B — Integrity
Rationale: Integrity ensures information remains accurate, complete, and protected from
unauthorized modification.
SECTION 2: RISK MANAGEMENT AND
GOVERNANCE
Questions 11–20
11. What is risk generally considered to be?
A. Threat × vulnerability × impact
B. Asset × password
C. Firewall × antivirus
D. Vulnerability ÷ user
Answer: A — Threat × vulnerability × impact
Rationale: Risk assessment commonly considers the likelihood of a threat exploiting a
vulnerability and the resulting impact. Different frameworks may express the calculation
differently, but these are core risk components.
12. What is a vulnerability?
A. A potential source of harm
B. A weakness that can be exploited
C. The financial loss caused by an attack
D. A security policy
Comprehensive Practice Questions &
Answers | Detailed Rationales | Exam-
Focused Study Guide |Instant
Downloaded PDF
SECTION 1: INFORMATION SECURITY
FUNDAMENTALS
Questions 1–10
1. Which three principles form the CIA triad?
A. Confidentiality, Integrity, Availability
B. Control, Identification, Authentication
C. Confidentiality, Identification, Authorization
D. Control, Integrity, Authentication
Answer: A — Confidentiality, Integrity, Availability
Rationale: The CIA triad is the fundamental model of information security. Confidentiality
prevents unauthorized disclosure, integrity protects information from unauthorized alteration,
and availability ensures authorized users can access information when needed.
2. Which security principle ensures that information is accessible when
required?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: C — Availability
Rationale: Availability ensures systems, applications, and information remain accessible to
authorized users when required.
,3. Which control primarily prevents unauthorized disclosure of information?
A. Confidentiality
B. Availability
C. Redundancy
D. Non-repudiation
Answer: A — Confidentiality
Rationale: Confidentiality protects sensitive information from being accessed or disclosed by
unauthorized individuals.
4. What is the primary purpose of authentication?
A. Determine what a user can access
B. Verify the identity of a user
C. Encrypt user information
D. Monitor network traffic
Answer: B — Verify the identity of a user
Rationale: Authentication establishes that a person or system is who or what it claims to be.
Authorization determines what that authenticated entity is allowed to do.
5. Which process determines what resources an authenticated user may
access?
A. Authentication
B. Authorization
C. Identification
D. Accounting
Answer: B — Authorization
Rationale: Authorization occurs after authentication and determines permissions and access
rights.
6. Which of the following is an example of something you know?
A. Fingerprint
B. Smart card
,C. Password
D. Security token
Answer: C — Password
Rationale: Authentication factors are commonly categorized as something you know, have,
or are. A password is something you know.
7. What is non-repudiation intended to provide?
A. Proof that an action or transaction occurred and cannot easily be denied
B. Faster network performance
C. Protection against malware
D. Physical protection of servers
Answer: A — Proof that an action or transaction occurred and cannot easily be denied
Rationale: Non-repudiation provides evidence linking an action or transaction to its
originator, commonly through mechanisms such as digital signatures and audit records.
8. Which security concept involves limiting users to only the access necessary
for their jobs?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Open access
Answer: B — Least privilege
Rationale: Least privilege gives users, applications, and processes only the permissions
necessary to perform their authorized tasks.
9. What is defense in depth?
A. Using one extremely strong security control
B. Eliminating all security controls except firewalls
C. Using multiple layers of security controls
D. Allowing unrestricted access
Answer: C — Using multiple layers of security controls
, Rationale: Defense in depth assumes that individual controls can fail and therefore uses
multiple complementary layers of protection.
10. Which security objective is primarily concerned with preventing
unauthorized modification?
A. Availability
B. Integrity
C. Confidentiality
D. Authentication
Answer: B — Integrity
Rationale: Integrity ensures information remains accurate, complete, and protected from
unauthorized modification.
SECTION 2: RISK MANAGEMENT AND
GOVERNANCE
Questions 11–20
11. What is risk generally considered to be?
A. Threat × vulnerability × impact
B. Asset × password
C. Firewall × antivirus
D. Vulnerability ÷ user
Answer: A — Threat × vulnerability × impact
Rationale: Risk assessment commonly considers the likelihood of a threat exploiting a
vulnerability and the resulting impact. Different frameworks may express the calculation
differently, but these are core risk components.
12. What is a vulnerability?
A. A potential source of harm
B. A weakness that can be exploited
C. The financial loss caused by an attack
D. A security policy