312-50 exam dumps

312-50 practice question 1 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 1

Single answer▪ Information Security Overview

A healthcare company is moving part of its patient scheduling system to a web-based platform. During a security review, management says the biggest concern is that appointment records must not be altered by unauthorized users, even if the system remains online and the data is not leaked. As the ethical hacker advising the project team, which security objective should be prioritized to address this concern?

  1. A

    Confidentiality, because the main goal is to prevent unauthorized disclosure of patient scheduling data

  2. B

    Integrity, because the primary concern is preventing unauthorized modification of appointment records

  3. C

    Availability, because keeping the scheduling platform accessible is the most important requirement

  4. D

    Non-repudiation, because the organization needs proof that users cannot deny scheduling changes they made

Show answer and explanation

Correct answer: B

Explanation

This question tests applied understanding of core information security objectives, especially the CIA triad: confidentiality, integrity, and availability. In CEH and general security practice, integrity refers to protecting information from improper modification or destruction and ensuring authenticity and accuracy. Because the scenario emphasizes preventing unauthorized changes to appointment records, integrity is the correct priority. Confidentiality would be the priority if the concern were unauthorized viewing of patient data; availability would apply if the concern were outages or denial-of-service conditions; and non-repudiation supports accountability after actions occur but is not the primary control objective described. This aligns with common guidance from NIST, including the definition of integrity in NIST SP 800-12 and broader foundational security principles used throughout security architecture and ethical hacking assessments.

  • A. Incorrect.

    This is incorrect. Confidentiality focuses on preventing unauthorized access or disclosure of information. While patient-related data often has confidentiality requirements, the scenario specifically states that the main concern is unauthorized alteration of records rather than data exposure.

  • B. Correct.

    This is correct. Integrity ensures that data remains accurate, complete, and unaltered except by authorized actions. In this scenario, management is specifically worried that appointment records could be changed by unauthorized users, which is a direct integrity issue within the CIA triad.

  • C. Incorrect.

    This is incorrect. Availability ensures systems and data are accessible when needed. The scenario explicitly says the concern remains even if the system stays online, meaning uptime is not the primary issue being tested here.

  • D. Incorrect.

    This is incorrect. Non-repudiation provides evidence of an action so a user cannot later deny performing it, often through logs, digital signatures, and audit trails. Although useful for accountability, it does not directly address the main requirement of preventing unauthorized modification in the first place.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam