TechKnowSurge
CompTIA Security+ 1.2 CompTIA Tech+ 6.1 CompTIA Security+ 2.4
InteractiveSecurityFree

CIA Triad Scenario Sorter

Classify breach scenarios by which CIA Triad property was violated: Confidentiality, Integrity, or Availability.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Three words carry the whole security curriculum, and this is where they get their meaning. Confidentiality is about who can see the data. Integrity is about whether the data is still what it was. Availability is about whether anyone can reach it at all. Every breach in the news lands somewhere in those three, and naming which one is the first move an analyst makes. The sorting is easier than it looks once the question is the right one. The question is not how bad the incident was, or how it happened — phishing, misconfiguration and malware turn up in all three bins. The question is what actually changed for the data. A customer database posted publicly, credentials pulled off unencrypted traffic, salary data forwarded to a personal Gmail, medical records opened by a stranger, an S3 bucket left readable: in all five the data is intact and the service is up. Somebody simply saw it who should not have. That is Confidentiality, every time. The Integrity five look superficially similar — an attacker got in — but the data is different afterwards. Wire transfer details rewritten, drug dosages altered, audit log entries edited, an order changed in transit, product prices modified. Nobody is locked out, and in most of these nothing has been stolen. The damage is that the record now lies, which is worse than losing it: a missing record is obviously missing, and a wrong one is trusted. The Availability five never touch the contents at all. A DDoS, a SYN flood, a power cut with no generator failover, a firewall rule that shuts the whole company out — the data is exactly as accurate and exactly as private as it was, and none of that helps anyone who cannot get to it. Two of those are not attacks in the first place. The outage and the firewall are a failure and a mistake, and they belong in the bin just the same, which is the point: the triad classifies impact, not intent. Ransomware is the one that will not sit still. Encrypting every file makes the data unreachable, so Availability is the primary answer and the one this activity grades. But ransomware crews routinely copy the data out before they encrypt it and threaten to publish, which is a Confidentiality breach, and files rewritten as ciphertext are no longer the records they were, which touches Integrity. All three are genuinely in play. Sorting it under Availability is not a claim that the other two are absent — it is a claim about what the victim notices first and what the attacker is actually selling back. Real incidents rarely violate exactly one property. The triad is a set of lenses, not a set of boxes.

What you'll learn

Aligned to

CompTIA Security+
1.2 Summarize fundamental security concepts.
2.4 Given a scenario, analyze indicators of malicious activity.
CompTIA Tech+
6.1 Summarize confidentiality, integrity, and availability concerns.

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Data Breach
An incident in which protected or sensitive data is accessed, stolen, or disclosed without authorization, typically triggering legal notification requirements.
Denial of Service
DoS
An attack that floods a system or network with traffic to make it unavailable to legitimate users.
Ransomware
A type of malware that encrypts a victim's files and demands payment in exchange for the decryption key.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →