WHAT YOU WILL LEARN
Learning objectives
- Distinguish confidentiality, integrity and availability
- Explain preventive and detective controls
- Connect a control to a specific risk
CIA describes different needs
Confidentiality limits unauthorised disclosure. Integrity addresses unauthorised or unintended modification. Availability concerns access to systems and information when needed. A scenario can affect more than one objective, so identify the primary problem before selecting a control.
Controls need context
A preventive control reduces the chance of an event, while a detective control helps identify it. Corrective measures support recovery. The same technology may support several purposes depending on how it is used. Explain what the control does in the scenario rather than matching a keyword alone.
Reason from the objective
Ask what asset matters, what threat and weakness are relevant, and what outcome is unacceptable. Consider operational constraints and the evidence available. A strong answer explains why one action is the best next step in that context.
APPLIED EXAMPLE
Put it in context
A clinic can read a patient record but its medication field has changed unexpectedly. Integrity is the immediate concern; availability alone does not establish that the record is trustworthy.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Equating encryption with every security objective
- Choosing a tool before defining the problem
- Treating an acronym as an explanation
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Security reasoning starts with the objective and the scenario. These lessons are independent educational preparation, not official certification material.