312-50 exam dumps

312-50 practice question 2 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 2

Single answer▪ Information Security Overview

A healthcare company is preparing to roll out a new patient portal that allows customers to view medical records and pay bills online. During a security planning meeting, management states that the main goal is to prevent unauthorized users from viewing patient data, ensure records are not altered in transit, and keep the portal available during peak usage. As the ethical hacker advising the team, which information security model best summarizes these three primary objectives for the portal?

  1. A

    The CIA triad: confidentiality, integrity, and availability

  2. B

    The AAA framework: authentication, authorization, and accounting

  3. C

    The Parkerian Hexad: possession, authenticity, utility, confidentiality, integrity, and availability

  4. D

    The non-repudiation model: proof of origin, proof of delivery, and accountability

Show answer and explanation

Correct answer: A

Explanation

The best answer is the CIA triad because the scenario explicitly describes its three elements: preventing unauthorized access to patient data corresponds to confidentiality, preventing improper modification of records corresponds to integrity, and keeping the portal accessible corresponds to availability. In information security overview topics, the CIA triad is the foundational model used to classify security objectives and guide control selection. This is consistent with common security guidance such as NIST principles for protecting information and systems, where confidentiality, integrity, and availability are treated as fundamental security objectives. AAA and non-repudiation are important supporting concepts, and the Parkerian Hexad is a valid extended model, but for CEH-style foundational application questions, the direct and best fit is the CIA triad.

  • A. Correct.

    Correct. The scenario directly maps to the three core principles of the CIA triad: confidentiality protects patient data from unauthorized disclosure, integrity ensures records are not altered improperly, and availability ensures the portal remains accessible to authorized users when needed. In CEH and general security practice, the CIA triad is the foundational model used to describe these primary information security objectives.

  • B. Incorrect.

    Incorrect. AAA is an important access control and identity management framework, but it does not directly summarize the three broad security goals described in the scenario. Authentication verifies identity, authorization determines permitted actions, and accounting logs activity. These controls support security, but they are not the overarching objectives being asked about here.

  • C. Incorrect.

    Incorrect. The Parkerian Hexad is a broader model that extends beyond the CIA triad and includes additional concepts such as possession, authenticity, and utility. While it is a legitimate information security model, the question asks for the model that best summarizes the three specific objectives stated by management. Those objectives exactly align with the CIA triad, making this option unnecessarily broad and not the best answer.

  • D. Incorrect.

    Incorrect. Non-repudiation is a specific security property that helps prove that an action or communication occurred and cannot later be denied. Although accountability-related controls are useful in healthcare environments, they do not represent the three main objectives listed in the scenario. This option reflects a common misconception of confusing one security service with the full set of core information security goals.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam