MANAGEMENT PLAN — PRACTICE 350
QUESTION AND ANSWERS BANK WITH
RATIONALES LATEST UPDATE
SECTION 1: CYBERSECURITY GOVERNANCE AND STRATEGY
Question 1: A cybersecurity management plan's primary purpose is to:
A) Eliminate all cyber threats
B) Serve as a static document for auditors
C) Align security initiatives with business objectives
D) Detail the technical specifications of firewall rules
Answer: C
Rationale: A management plan is a strategic document that bridges business goals
and security operations, ensuring resources support the organization's mission.
Security is not about elimination of all threats—that is impossible—but about
managing risk in alignment with business priorities.
Question 2: Which element is most critical for building a cyberssecurityaware
culture?
A) Punitive policies for repeat offenders
B) Executive leadership endorsement and modeling
C) Mandatory quarterly security newsletters
D) Outsourcing all awareness training
1
,Answer: B
Rationale: Culture starts at the top. When executives visibly champion security and
follow protocols, it signals organizational values, making awareness efforts
credible. Punitive measures alone do not build culture, and outsourcing does not
demonstrate organizational commitment.
Question 3: A company's Board of Directors is primarily responsible for which
aspect of cybersecurity?
A) Configuring intrusion detection systems
B) Approving the risk appetite and providing strategic oversight
C) Conducting daily threat intelligence analysis
D) Managing thirdparty vendor patching schedules
Answer: B
Rationale: The board governs risk. Their role is fiduciary oversight, setting the
"tone at the top" and accepting the level of residual risk the organization will bear.
Technical configuration and daily operations are managementlevel responsibilities.
Question 4: When developing a cybersecurity strategy, a gap analysis is used to:
A) Identify differences between current security posture and a desired future state
B) Scan for open ports on the external network perimeter
C) Calculate the annual loss expectancy of a specific asset
D) Document the chain of custody for digital evidence
Answer: A
Rationale: A gap analysis benchmarks the "asis" state against the "tobe" state,
revealing missing controls or capabilities that the management plan must address.
2
,Question 5: Governance in cybersecurity is best defined as:
A) The act of installing security patches on servers
B) A set of responsibilities and practices exercised to provide strategic direction
and ensure objectives are achieved
C) A penetration testing methodology
D) The process of encrypting data at rest
Answer: B
Rationale: Governance is the decisionmaking framework that ensures security
strategy aligns with business strategy, risks are managed appropriately, and
resources are used responsibly.
Question 6: Which of the following best describes the relationship between
governance and management in cybersecurity?
A) Governance and management are the same function
B) Governance sets direction and oversight; management implements and
executes
C) Management sets policy; governance enforces it
D) There is no relationship between governance and management
Answer: B
Rationale: Governance provides the framework, oversight, and strategic direction,
while management is responsible for implementing the controls, policies, and
procedures that operationalize governance decisions.
Question 7: A security strategy that fails to consider business objectives is most
likely to result in:
3
, A) Overinvestment in security controls that do not protect critical assets
B) Complete elimination of all security risks
C) Reduced need for compliance audits
D) Increased employee productivity
Answer: A
Rationale: Security investments must be prioritized based on business impact.
Without alignment to business objectives, resources may be wasted on controls
that do not address the organization's most significant risks.
Question 8: The primary difference between a policy and a procedure is:
A) Policies are technical; procedures are administrative
B) Policies state what must be done; procedures detail how to do it
C) Policies are optional; procedures are mandatory
D) There is no difference
Answer: B
Rationale: Policies are highlevel statements of management intent and
expectations. Procedures provide the step by step instructions for implementing
policies.
Question 9: Which role is typically responsible for the day to day implementation
of security controls?
A) Board of Directors
B) Chief Information Security Officer (CISO)
C) Security Manager
D) Chief Executive Officer
4