ITPEC FE Subject A April 2025 Question 45
ITPEC FE Subject A April 2025 — Question 45 of 60
The question asks which checkpoint an auditor uses to assess controls against information leakage and unauthorized use of system documents.
Both "leakage" and "unauthorized use" point directly to confidentiality — making (c) the correct answer.
Why not others:
- (a) Creating documents even in prototype development — relates to documentation completeness, not protection against leakage
- (b) Standardizing documents — relates to quality and consistency, not security
- (d) Updating documents without delay — relates to integrity and accuracy, not confidentiality
Key rule: Map risk keywords to the CIA triad — "leakage" and "unauthorized use" always map to Confidentiality.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.