CRISC Practice Questions
CIA Triad and IAAA - 60 Questions
Interactive Quiz
Question 1 of 60
0%
Score: 0
Correct: 0
Wrong: 0
Part 1: CIA Triad
1 What does the CIA triad stand for in information security?
Answer: B - Confidentiality, Integrity, Availability
The CIA triad consists of Confidentiality, Integrity, and Availability - the three core pillars of information security.
2 Which principle of the CIA triad ensures that data is accessible to authorized users when needed?
Answer: A - Availability
Availability ensures that systems, data, and services are accessible to authorized users whenever required. It protects against disruptions such as DoS attacks or system failures.
3 Which principle ensures that data has not been altered or tampered with in an unauthorized manner?
Answer: C - Integrity
Integrity ensures that data is accurate, complete, and has not been altered or destroyed in an unauthorized manner. It protects against unauthorized modification.
4 Encryption is PRIMARILY used to protect which principle of the CIA triad?
Answer: D - Confidentiality
Encryption protects confidentiality by making data unreadable to unauthorized parties. Only those with the proper decryption key can access the plaintext.
5 A checksum or hash is PRIMARILY used to verify which principle?
Answer: B - Integrity
Checksums and hashes verify integrity by detecting whether data has been altered. Even a small change produces a completely different hash value.
6 A Distributed Denial of Service (DDoS) attack PRIMARILY impacts which principle?
Answer: A - Availability
A DDoS attack overwhelms systems with traffic, making them unavailable to legitimate users. It primarily targets availability.
7 Which of the following is the BEST example of a confidentiality control?
Answer: C - Access control lists and encryption
Access control lists and encryption protect confidentiality by preventing unauthorized access to data. Backup power and RAID protect availability, and digital signatures protect integrity.
8 Which of the following is the BEST example of an availability control?
Answer: B - Redundant servers and failover systems
Redundant servers and failover systems ensure that services remain available even if primary systems fail. They primarily protect availability.
9 Which of the following is the BEST example of an integrity control?
Answer: D - Digital signatures and hash verification
Digital signatures and hash verification ensure that data has not been altered. They protect integrity by detecting unauthorized changes.
10 Which principle of the CIA triad is MOST directly related to data being accurate and trustworthy?
Answer: A - Integrity
Integrity ensures that data is accurate, complete, and trustworthy. It protects against unauthorized modification or corruption of data.
11 Which of the following would be considered a BREACH of confidentiality?
Answer: C - An employee shares sensitive customer data with an unauthorized third party
Unauthorized disclosure of sensitive data is a breach of confidentiality. The other options affect availability or integrity.
12 Which of the following would be considered a BREACH of integrity?
Answer: B - A user modifies a financial record without authorization
Unauthorized modification of data is a breach of integrity. Sharing passwords affects confidentiality, while downtime and drive failure affect availability.
13 Which of the following would be considered a BREACH of availability?
Answer: D - A ransomware attack encrypts critical data, making it inaccessible
Ransomware makes data and systems unavailable to authorized users, which is a breach of availability. It may also affect confidentiality if data is exfiltrated.
14 Which of the following is a common threat to confidentiality?
Answer: A - Eavesdropping and unauthorized access
Eavesdropping, interception, and unauthorized access are common threats to confidentiality. The other options primarily threaten availability.
15 Which of the following is a common threat to integrity?
Answer: C - Man-in-the-middle (MITM) attacks modifying data in transit
MITM attacks can modify data in transit, which is a threat to integrity. Power failures and DDoS threaten availability, and laptop theft threatens confidentiality.
16 Which of the following is a common threat to availability?
Answer: B - Ransomware and DDoS attacks
Ransomware and DDoS attacks are common threats to availability. Keyloggers and shoulder surfing threaten confidentiality, and unauthorized modification threatens integrity.
17 Which of the following BEST describes the relationship among the three CIA principles?
Answer: D - They are interdependent and must be balanced based on business needs
The three principles are interdependent and must be balanced. Stronger confidentiality controls (e.g., encryption) can sometimes affect availability or performance. A risk-based approach is needed.
18 Which of the following is a good practice for protecting data integrity?
Answer: A - Implementing version control and change detection mechanisms
Version control, change detection, and file integrity monitoring help protect data integrity by detecting unauthorized changes. The other options weaken security.
19 Which of the following BEST describes the goal of confidentiality?
Answer: C - To ensure data is accessed only by authorized individuals
Confidentiality ensures that data is accessible only to authorized individuals, protecting it from unauthorized disclosure.
20 A digital signature PRIMARILY provides which two security properties?
Answer: B - Integrity and non-repudiation
A digital signature provides integrity (proving the data has not been altered) and non-repudiation (proving the signer cannot deny having signed the data).
21 Which of the following is a good practice for protecting availability?
Answer: D - Implementing redundancy, backups, and disaster recovery plans
Redundancy, backups, and disaster recovery plans help ensure availability by allowing systems to recover quickly from failures or disruptions.
22 Which of the following is MOST critical for maintaining data availability?
Answer: A - A tested business continuity and disaster recovery plan
A tested BCP/DRP is critical for availability. It ensures the organization can recover and continue operations after a disruption. The other options protect confidentiality or integrity.
23 Which of the following BEST describes how the CIA triad supports business objectives?
Answer: C - It provides a framework for protecting information assets that support business objectives
The CIA triad provides a framework for identifying and protecting information assets that support business objectives. It does not replace risk management, policies, or compliance efforts.
24 A company stores customer credit card data. Which CIA principle is MOST critical for regulatory compliance such as PCI DSS?
Answer: B - Confidentiality
For credit card data, confidentiality is paramount. PCI DSS requires strong protections to prevent unauthorized access to cardholder data. However, all three principles are important.
25 A hospital's patient record system must ensure that medical records are accurate and cannot be altered. This is an example of protecting which principle?
Answer: A - Integrity
Ensuring medical records are accurate and cannot be altered is a matter of integrity. This is critical in healthcare for patient safety and legal reasons.
26 An e-commerce website must remain online during peak shopping periods. This is an example of protecting which principle?
Answer: D - Availability
Ensuring an e-commerce website remains online during peak periods is a matter of availability. Downtime directly impacts revenue and customer trust.
27 Which of the following is a KEY consideration when balancing the CIA triad?
Answer: C - Balance the principles based on business needs, risk, and regulatory requirements
The CIA principles must be balanced based on business needs, risk appetite, and regulatory requirements. There is no universal priority - it depends on the context.
28 Which of the following BEST describes "non-repudiation"?
Answer: B - The assurance that a party cannot deny the authenticity of their signature or message
Non-repudiation ensures that a party cannot deny having sent a message or performed an action. It is typically provided by digital signatures and audit logs.
29 Which of the following is the BEST example of a technical control that protects confidentiality?
Answer: A - Data encryption at rest and in transit
Encryption at rest and in transit protects confidentiality by making data unreadable to unauthorized parties. The other options primarily protect availability.
30 Which of the following BEST describes how CIA triad principles relate to risk management?
Answer: D - They help identify and prioritize risks to information assets based on business impact
The CIA triad helps identify and prioritize risks to information assets. Loss of confidentiality, integrity, or availability can have significant business impacts.
31 What does the acronym IAAA stand for in information security?
Answer: B - Identification, Authentication, Authorization, Accountability
IAAA stands for Identification, Authentication, Authorization, and Accountability - the four pillars of access control and identity management.
32 What is the PRIMARY purpose of identification in the IAAA model?
Answer: A - To claim an identity (such as a username) before authentication
Identification is the process of claiming an identity, typically via a username, email address, or ID number. It is the first step in the IAAA process, followed by authentication.
33 What is the PRIMARY purpose of authentication?
Answer: C - To verify that a claimed identity is valid
Authentication verifies that the identity claimed during identification is genuine. It typically involves something the user knows (password), has (token), or is (biometric).
34 What is the PRIMARY purpose of authorization?
Answer: D - To determine what resources and actions a verified user is permitted to access or perform
Authorization determines what a verified user can do - which resources they can access and what actions they can perform. It occurs after successful authentication.
35 What is the PRIMARY purpose of accountability in the IAAA model?
Answer: B - To trace actions back to a specific user through logging and auditing
Accountability ensures that every action can be traced back to a specific user. It is achieved through logging, monitoring, and auditing. It relies on unique identification.
36 Which of the following is the CORRECT sequence of the IAAA model?
Answer: A - Identification, Authentication, Authorization, Accountability
The correct sequence is: (1) Identification - claim identity, (2) Authentication - verify identity, (3) Authorization - determine access, (4) Accountability - log and audit actions.
37 Which of the following is the BEST example of authentication?
Answer: C - Entering a password or scanning a fingerprint
Entering a password or scanning a fingerprint is authentication - it verifies the identity claimed during identification. Entering a username is identification.
38 Which of the following is the BEST example of identification?
Answer: D - Entering a username on a login screen
Entering a username is identification - the user claims an identity. Password entry or fingerprint scanning is authentication, which verifies the claimed identity.
39 Which of the following is the BEST example of authorization?
Answer: B - Being granted read-only access to a financial report
Authorization determines what a verified user can access. Being granted read-only access to a specific file is an example of authorization.
40 Which of the following is the BEST example of accountability?
Answer: A - Audit logs that record who accessed a system and what actions they performed
Accountability is achieved through logging and auditing. Audit logs trace actions back to specific users, providing accountability for their actions.
41 Which of the following is a common factor of authentication?
Answer: C - Something you know, something you have, something you are
The three classic authentication factors are: something you know (password, PIN), something you have (token, smart card), and something you are (biometrics).
42 What is multi-factor authentication (MFA)?
Answer: B - Using two or more different authentication factors (e.g., password plus fingerprint)
MFA requires two or more different types of authentication factors - for example, a password (something you know) plus a fingerprint (something you are). Two passwords are not MFA; they are the same factor type.
43 Which of the following BEST describes the principle of least privilege?
Answer: D - Giving users only the minimum access necessary to perform their job functions
Least privilege means granting users only the minimum access required to perform their job. This reduces the attack surface and limits the impact of compromised accounts.
44 Which of the following is a common authorization model?
Answer: A - Role-Based Access Control (RBAC)
RBAC is a common authorization model where access is granted based on a user's role in the organization. Other authorization models include MAC, DAC, and ABAC.
45 Which of the following is a KEY benefit of accountability in the IAAA model?
Answer: C - It deters malicious activity and supports forensic investigations
Accountability deters malicious activity (users know their actions are logged) and supports forensic investigations (actions can be traced to specific users).
46 Which of the following is an example of "something you have" as an authentication factor?
Answer: B - A smart card or hardware token
"Something you have" refers to a physical object the user possesses, such as a smart card, hardware token, or mobile device. Passwords and PINs are "something you know."
47 Which of the following is an example of "something you are" as an authentication factor?
Answer: D - A fingerprint or retina scan
"Something you are" refers to biometric characteristics such as fingerprints, retina patterns, or voice. These are unique to the individual.
48 What is the PRIMARY risk of weak authentication?
Answer: A - Unauthorized users can impersonate legitimate users and access sensitive resources
Weak authentication allows attackers to impersonate legitimate users, gaining unauthorized access to systems and data. This is a serious security risk.
49 Which of the following is a KEY characteristic of strong authentication?
Answer: C - It combines multiple factors for greater assurance
Strong authentication combines multiple factors (something you know, have, or are) to increase the assurance that the user is who they claim to be.
50 Which of the following BEST describes the relationship between authentication and authorization?
Answer: B - Authentication verifies identity; authorization determines what that identity can access
Authentication verifies who you are; authorization determines what you can do. Authentication must occur before authorization.
51 Which of the following is a common access control principle related to authorization?
Answer: D - Least privilege and need-to-know
Least privilege (minimum access needed for the job) and need-to-know (access only to information required for a task) are key authorization principles.
52 Which of the following BEST describes why unique user IDs are important?
Answer: A - They enable accountability by ensuring actions can be traced to a specific individual
Unique user IDs are essential for accountability. Shared accounts make it impossible to trace actions to a specific individual, undermining accountability.
53 Which of the following is a KEY risk associated with shared accounts?
Answer: C - Loss of accountability since actions cannot be attributed to a specific individual
Shared accounts undermine accountability. When multiple users share an account, it is impossible to determine who performed a specific action, which is a serious control weakness.
54 Which of the following is a common authentication protocol?
Answer: B - Kerberos
Kerberos is a network authentication protocol that uses tickets to allow nodes to prove their identity securely. RBAC is an authorization model, ACL is an access control list, and VPN is a secure tunnel.
55 Which of the following is a common authentication protocol used for web applications?
Answer: D - SAML and OAuth
SAML and OAuth are widely used authentication and authorization protocols for web applications and single sign-on (SSO). FTP, SMTP, and HTTP are not authentication protocols.
56 Which of the following is a key benefit of Single Sign-On (SSO)?
Answer: A - Users authenticate once and gain access to multiple systems, improving usability and reducing password fatigue
SSO allows users to authenticate once and access multiple systems without re-entering credentials. It improves usability and reduces password fatigue, but it also introduces a single point of failure if not properly implemented.
57 Which of the following BEST describes the concept of "federated identity"?
Answer: C - A user's identity is shared across multiple independent systems or organizations based on trust
Federated identity allows a user's identity to be shared across multiple systems or organizations based on trust relationships. It enables SSO across organizational boundaries.
58 Which of the following is a KEY control to ensure accountability?
Answer: B - Enabling logging and monitoring of all user activities
Logging and monitoring are essential for accountability. They record user activities, enabling the organization to trace actions back to specific individuals.
59 Which of the following BEST describes the concept of "identity proofing"?
Answer: A - The process of verifying a person's identity before issuing credentials
Identity proofing is the process of verifying a person's identity before issuing credentials. It ensures the right person receives the right credentials. It is a critical step in the IAAA model.
60 Which of the following BEST describes how the IAAA model supports the CIA triad?
Answer: D - IAAA provides the access control foundation that supports confidentiality, integrity, and availability
IAAA (Identification, Authentication, Authorization, Accountability) provides the access control foundation that supports the CIA triad. For example, authentication and authorization protect confidentiality, while accountability supports integrity.
🏆
Quiz Complete!
0 / 60
0
Correct
0
Wrong
60
Total
Quick Reference Summary
| Concept | Definition | Key Examples |
|---|---|---|
| Confidentiality | Data accessible only to authorized parties | Encryption, access controls, data classification |
| Integrity | Data is accurate and unaltered | Hashing, digital signatures, version control |
| Availability | Data accessible when needed | Redundancy, backups, DRP, DDoS protection |
| Identification | Claiming an identity | Username, email, ID number |
| Authentication | Verifying an identity | Password, biometrics, tokens, MFA |
| Authorization | Determining what an identity can access | RBAC, MAC, DAC, least privilege |
| Accountability | Tracing actions to specific users | Audit logs, monitoring, non-repudiation |
Exam Tips
- CIA Triad - Confidentiality (secrecy), Integrity (accuracy), Availability (accessibility).
- Confidentiality controls - Encryption, access controls, data classification.
- Integrity controls - Hashing, digital signatures, file integrity monitoring.
- Availability controls - Redundancy, backups, DRP, load balancing.
- IAAA sequence - Identification, Authentication, Authorization, Accountability.
- Authentication factors - Something you know, have, or are.
- MFA - Two or more DIFFERENT factor types (not two passwords).
- Least privilege - Minimum access needed for the job.
- Accountability - Requires unique IDs and logging; shared accounts break it.
- Digital signatures - Provide integrity AND non-repudiation.






0 $type={blogger}:
Post a Comment