Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 94 pages
Exam (elaborations)

CITP Study Guide 2026/2027 | Information Security, Cyber Risks, Data Management & IT Governance

Document preview thumbnail
Preview 4 out of 94 pages

CITP Study Guide 2026/2027 | Information Security, Cyber Risks, Data Management & IT Governance

Content preview

CITP Study Guide 2026/2027 | Information Security, Cyber
Risks, Data Management & IT Governance


Section 1: Information Security Fundamentals
1. What is the primary objective of information security?
A. Increase internet bandwidth
B. Protect information and information systems from threats
C. Eliminate all technology costs
D. Replace business processes
Answer: B
Rationale: Information security protects information and systems
against unauthorized access, use, disclosure, disruption, modification,
or destruction.
2. Which three principles form the classic CIA triad?
A. Control, Inspection, Authorization
B. Confidentiality, Integrity, Availability
C. Compliance, Information, Authentication
D. Cybersecurity, Identification, Accountability
Answer: B
Rationale: Confidentiality, integrity, and availability are the foundational
objectives of information security.
3. Which security principle prevents unauthorized disclosure of
information?
A. Integrity
B. Availability
C. Confidentiality

,D. Nonrepudiation
Answer: C
Rationale: Confidentiality ensures information is accessible only to
authorized individuals or systems.
4. Which principle ensures information has not been improperly
altered?
A. Integrity
B. Availability
C. Confidentiality
D. Resilience
Answer: A
Rationale: Integrity protects information from unauthorized or
improper modification.
5. Availability means that information should be:
A. Encrypted at all times
B. Accessible when authorized users need it
C. Available to everyone
D. Stored only offline
Answer: B
Rationale: Availability ensures authorized users can access systems and
information when required.
6. What is a security control?
A. A database record
B. A safeguard used to manage risk
C. A programming language
D. A network cable
Answer: B

,Rationale: Security controls are measures designed to prevent, detect,
correct, or reduce security risks.
7. Which is an example of a preventive control?
A. Security incident report
B. Firewall rule
C. Post-incident review
D. Audit finding
Answer: B
Rationale: Firewalls can prevent unauthorized network traffic from
reaching protected systems.
8. Which control is primarily detective?
A. Intrusion detection system
B. Password policy
C. Encryption
D. Network segmentation
Answer: A
Rationale: An IDS detects and alerts on potentially malicious activity.
9. Which is a corrective control?
A. Backup restoration after data loss
B. Password complexity requirement
C. Security awareness training
D. Firewall filtering
Answer: A
Rationale: Corrective controls restore systems or reduce the effects of
an incident.
10. What does defense in depth mean?
A. Using one very strong control

, B. Using multiple layers of security controls
C. Removing redundant controls
D. Outsourcing security
Answer: B
Rationale: Defense in depth uses multiple complementary controls so
failure of one does not expose the organization completely.
11. What is the principle of least privilege?
A. Users receive administrator privileges by default
B. Users receive only the access necessary to perform their duties
C. Everyone receives identical permissions
D. Privileges never expire
Answer: B
Rationale: Least privilege reduces the potential damage caused by
misuse or compromise of an account.
12. What is separation of duties designed to prevent?
A. Network congestion
B. One individual controlling an entire sensitive process
C. Software updates
D. Data backups
Answer: B
Rationale: Separating responsibilities reduces fraud, abuse, and
unauthorized activity.
13. What does nonrepudiation provide?
A. Faster networks
B. Evidence that a party performed or approved an action
C. Unlimited access
D. Password recovery

Document information

Uploaded on
September 15, 2026
Number of pages
94
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(24)
Sold
113
Followers
3
Items
8661
Last sold
17 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions