Examination Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
1. Which is the PRIMARY objective of IT governance?
A. Reduce hardware costs
B. Ensure alignment between IT and business goals
C. Replace IT staff with automation
D. Eliminate all system risks
Correct Answer: B
Rationale: IT governance is primarily concerned with ensuring that IT
investments and operations align with organizational objectives. While cost
reduction and risk management are benefits, the core purpose is strategic
alignment between business goals and IT capabilities.
2. What is the MOST important purpose of an information security policy?
A. Define user salaries
B. Outline hardware specifications
C. Establish management direction for security
D. Replace operational procedures
Correct Answer: C
Rationale: A security policy provides high-level management direction and
expectations for protecting information assets. It does not define technical
specifications or detailed procedures but sets the foundation for all security
controls.
,3. Which control BEST prevents unauthorized access to systems?
A. Detective controls
B. Corrective controls
C. Preventive controls
D. Recovery controls
Correct Answer: C
Rationale: Preventive controls are designed to stop security incidents before
they occur. Examples include firewalls, authentication systems, and access
control mechanisms.
4. What is the PRIMARY purpose of risk assessment?
A. Eliminate all risks
B. Identify, analyze, and evaluate risks
C. Encrypt all organizational data
D. Replace internal audit
Correct Answer: B
Rationale: Risk assessment focuses on identifying threats, analyzing
vulnerabilities, and evaluating their potential impact to support informed
decision-making.
5. Which of the following BEST describes residual risk?
A. Risk eliminated by encryption
B. Risk remaining after controls are applied
C. Risk transferred to insurance
D. Risk not identified in audit
Correct Answer: B
Rationale: Residual risk is the level of risk that remains after mitigation
measures and controls have been implemented.
, 6. What is the PRIMARY purpose of an audit trail?
A. Increase system speed
B. Track user activities
C. Reduce storage usage
D. Replace backup systems
Correct Answer: B
Rationale: Audit trails record user and system activities to support
accountability, investigation, and compliance monitoring.
7. Which is the MOST effective authentication factor combination?
A. Password only
B. Username and password
C. Something you know, have, and are
D. Security questions only
Correct Answer: C
Rationale: Multi-factor authentication using knowledge, possession, and
biometric factors significantly increases security strength.
8. What is the MAIN purpose of segregation of duties?
A. Reduce training costs
B. Prevent fraud and errors
C. Increase system performance
D. Eliminate audit requirements
Correct Answer: B
Rationale: Segregation of duties ensures that no single individual has
control over all parts of a critical process, reducing risk of fraud and error.
9. Which type of control is a firewall?
A. Detective
B. Corrective