SY0-701 exam dumps

SY0-701 practice question 10 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 10

Single answerConfidentiality, Integrity, and Availability (CIA)

A healthcare organization stores patient records in a central database used by clinics in multiple states. During a recent incident review, the security team found three issues: database administrators can read all patient data in plaintext, a misconfigured application server was able to alter billing records without detection, and several clinics lost access to records for hours after a storage failure. Management wants to prioritize a control that most directly addresses the integrity issue identified in the review without primarily focusing on confidentiality or availability. Which control should the organization implement first?

  1. A

    Enable database activity monitoring and enforce least-privilege administrative roles

  2. B

    Implement digital signatures or hashing with file integrity monitoring on billing records

  3. C

    Deploy full-disk encryption on the database servers

  4. D

    Add database replication and redundant storage across multiple sites

Show answer and explanation

Correct answer: B

Explanation

The CIA triad separates security objectives into confidentiality, integrity, and availability. In this scenario, plaintext access by administrators is a confidentiality concern, unauthorized alteration of billing records without detection is an integrity concern, and clinic outages after a storage failure are an availability concern. Because the question asks for the control that most directly addresses integrity, the best answer is to implement digital signatures or hashing with file integrity monitoring on billing records. These controls help verify that data has not been altered improperly and support detection of tampering. This aligns with common security best practices and guidance such as NIST principles for protecting data integrity through checksums, hashes, and monitoring of unauthorized changes. The other options are valuable controls, but they primarily map to confidentiality or availability rather than the specific integrity gap described.

  • A. Incorrect.

    This would help reduce unnecessary access and improve confidentiality by limiting who can view sensitive records. Database activity monitoring can also support detection, but it does not most directly ensure that unauthorized changes to billing records are detectable or prevented from going unnoticed. A candidate might choose this because least privilege is an important security control, but in this scenario the question specifically asks for the control that most directly addresses integrity.

  • B. Correct.

    This is correct because integrity focuses on ensuring data is not altered in an unauthorized or undetected manner. Digital signatures, cryptographic hashes, and file integrity monitoring provide mechanisms to verify that billing records have not been tampered with and to detect unauthorized modifications. In the scenario, the core integrity problem is that records were altered without detection, so implementing integrity validation and monitoring is the most direct response.

  • C. Incorrect.

    Full-disk encryption protects data at rest and is primarily a confidentiality control. It helps if drives are stolen or improperly disposed of, but it does not address the problem of an authorized system or misconfigured server changing data in the database. This is a common misconception because encryption is often viewed as a general security fix, but it does not by itself ensure integrity of application data changes.

  • D. Incorrect.

    Replication and redundant storage are availability controls. They help maintain access to systems during outages or storage failures, which matches the clinics' inability to access records for hours. However, they do not directly solve the issue of billing records being modified without detection. Someone might pick this option because the scenario mentions outages, but the question explicitly asks for the control that best addresses integrity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam