Study for the ITIL 4 Foundation Exam with comprehensive multiple choice questions and flashcards. Each question offers hints and explanations. Ace your exam with confidence!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which of the following describes confidentiality?

  1. The ability to protect sensitive data from loss

  2. A security objective that ensures information is not disclosed to unauthorized entities

  3. A method to encrypt data during transmission

  4. A policy governing data retention

The correct answer is: A security objective that ensures information is not disclosed to unauthorized entities

Confidentiality refers specifically to the protection of sensitive information from being accessed or disclosed to unauthorized individuals or entities. It is one of the key principles of information security aimed at ensuring that only authorized users can view or access certain data. This is crucial in maintaining privacy and safeguarding information that could be harmful if it falls into the wrong hands, such as personal, financial, or proprietary data. While protecting sensitive data from loss can be considered part of a broader security strategy, it does not specifically address the aspect of unauthorized disclosure. Similarly, encryption during transmission is a method used to achieve confidentiality but does not define the concept itself. A policy governing data retention relates to the management of data rather than its confidentiality, focusing on how long data can be held and when it should be disposed of. Thus, the definition of confidentiality as the assurance that information is not disclosed to unauthorized parties encapsulates its essence and aligns with established information security principles.