About this interactive
Every region in this diagram shows the same attacker reaching the same kind of target — the difference between the three is entirely in what happens once they're in. The top region shows the data being read by someone who was never supposed to see it: nothing about the data changed and nothing went offline, it was simply exposed. That's Confidentiality. The middle region shows the data itself being rewritten — the content is now wrong, whether or not anyone even notices right away. That's Integrity. The bottom region shows the server knocked offline entirely: the data may be untouched and unseen by the attacker, but nobody who needs it can reach it. That's Availability.
The useful habit this diagram is built to train: don't classify a breach by who did it or how they got in. A single attacker, a single exploited vulnerability, can produce any of the three outcomes — classify by what the outcome actually did to the data.
What you'll learn
- Label a breach diagram's three outcomes — data read by an unauthorized party, data rewritten, and a system taken offline — with the CIA Triad property each one violates
- Distinguish a Confidentiality violation (the wrong party sees the data) from an Integrity violation (the data itself is changed) from an Availability violation (the data or system is not reachable)
Aligned to
NIST NICE
K0728
Knowledge of Confidentiality, Integrity and Availability (CIA) principles and practices
CompTIA Tech+
6.1
Summarize confidentiality, integrity, and availability concerns
ISC2 CC
1.1
Understand cybersecurity concepts
Cisco CCST Cybersecurity
1.1
Define essential security principles
Key terms
- CIA Triad
- The three core principles of information security: Confidentiality, Integrity, and Availability.
- Confidentiality
- The principle that information is accessible only to those authorized to access it.
- Integrity
- The assurance that data has not been tampered with and remains accurate and complete.
- Availability
- The assurance that systems and data are accessible and operational when needed by authorized users.
- Denial of Service
DoS
- An attack that floods a system or network with traffic to make it unavailable to legitimate users.
Topics
Interactive
Label Diagram
Cia Triad
Confidentiality
Integrity
Availability
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →