ARKANSAS CYBERSECURITY PROFESSIONAL
EXAM QUESTIONS WITH CORRECT ANSWERS
AND RATIONALES LATEST 2026-2027 UPDATE
Questions 1–10: Cybersecurity Fundamentals
1. What is the primary objective of cybersecurity?
A. Increasing network bandwidth
B. Protecting information and systems from unauthorized access,
disruption, alteration, or destruction
C. Eliminating all computer hardware
D. Reducing software development costs
Correct Answer: B
Rationale: Cybersecurity protects information systems and data against
threats to confidentiality, integrity, and availability.
2. Which three principles form the CIA triad?
A. Control, Inspection, Authentication
B. Confidentiality, Integrity, Availability
C. Cybersecurity, Intelligence, Authorization
D. Compliance, Investigation, Auditing
Correct Answer: B
Rationale: The CIA triad represents the three fundamental objectives of
information security: confidentiality, integrity, and availability.
,3. Which security principle ensures that information is accessible to
authorized users when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct Answer: C
Rationale: Availability ensures systems and information remain
accessible and operational for authorized users.
4. Which control is an example of preventive security?
A. Reviewing an incident after it occurs
B. Firewall blocking unauthorized traffic
C. Forensic analysis
D. Incident report
Correct Answer: B
Rationale: Preventive controls are designed to stop or reduce the
likelihood of security incidents before they occur.
5. What is authentication?
A. Determining what a user may access
B. Verifying a user's identity
C. Encrypting a database
D. Monitoring network traffic
Correct Answer: B
, Rationale: Authentication verifies that an individual or system is who or
what it claims to be.
6. What is authorization?
A. Establishing a user's identity
B. Determining what an authenticated user is permitted to do
C. Encrypting communications
D. Detecting malware
Correct Answer: B
Rationale: Authorization determines the resources and actions an
authenticated subject is allowed to access.
7. Which concept requires users to receive only the access necessary
to perform their duties?
A. Separation of duties
B. Least privilege
C. Open access
D. Mandatory disclosure
Correct Answer: B
Rationale: Least privilege minimizes unnecessary permissions and
limits potential damage from compromised accounts.
8. What is defense in depth?
A. Using one extremely powerful security control
B. Eliminating security controls that overlap
EXAM QUESTIONS WITH CORRECT ANSWERS
AND RATIONALES LATEST 2026-2027 UPDATE
Questions 1–10: Cybersecurity Fundamentals
1. What is the primary objective of cybersecurity?
A. Increasing network bandwidth
B. Protecting information and systems from unauthorized access,
disruption, alteration, or destruction
C. Eliminating all computer hardware
D. Reducing software development costs
Correct Answer: B
Rationale: Cybersecurity protects information systems and data against
threats to confidentiality, integrity, and availability.
2. Which three principles form the CIA triad?
A. Control, Inspection, Authentication
B. Confidentiality, Integrity, Availability
C. Cybersecurity, Intelligence, Authorization
D. Compliance, Investigation, Auditing
Correct Answer: B
Rationale: The CIA triad represents the three fundamental objectives of
information security: confidentiality, integrity, and availability.
,3. Which security principle ensures that information is accessible to
authorized users when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct Answer: C
Rationale: Availability ensures systems and information remain
accessible and operational for authorized users.
4. Which control is an example of preventive security?
A. Reviewing an incident after it occurs
B. Firewall blocking unauthorized traffic
C. Forensic analysis
D. Incident report
Correct Answer: B
Rationale: Preventive controls are designed to stop or reduce the
likelihood of security incidents before they occur.
5. What is authentication?
A. Determining what a user may access
B. Verifying a user's identity
C. Encrypting a database
D. Monitoring network traffic
Correct Answer: B
, Rationale: Authentication verifies that an individual or system is who or
what it claims to be.
6. What is authorization?
A. Establishing a user's identity
B. Determining what an authenticated user is permitted to do
C. Encrypting communications
D. Detecting malware
Correct Answer: B
Rationale: Authorization determines the resources and actions an
authenticated subject is allowed to access.
7. Which concept requires users to receive only the access necessary
to perform their duties?
A. Separation of duties
B. Least privilege
C. Open access
D. Mandatory disclosure
Correct Answer: B
Rationale: Least privilege minimizes unnecessary permissions and
limits potential damage from compromised accounts.
8. What is defense in depth?
A. Using one extremely powerful security control
B. Eliminating security controls that overlap