CITP Study Guide 2026/2027 | Information Security, Cyber
Risks, Data Management & IT Governance
Section 1: Information Security Fundamentals
1. What is the primary objective of information security?
A. Increase internet bandwidth
B. Protect information and information systems from threats
C. Eliminate all technology costs
D. Replace business processes
Answer: B
Rationale: Information security protects information and systems
against unauthorized access, use, disclosure, disruption, modification,
or destruction.
2. Which three principles form the classic CIA triad?
A. Control, Inspection, Authorization
B. Confidentiality, Integrity, Availability
C. Compliance, Information, Authentication
D. Cybersecurity, Identification, Accountability
Answer: B
Rationale: Confidentiality, integrity, and availability are the foundational
objectives of information security.
3. Which security principle prevents unauthorized disclosure of
information?
A. Integrity
B. Availability
C. Confidentiality
,D. Nonrepudiation
Answer: C
Rationale: Confidentiality ensures information is accessible only to
authorized individuals or systems.
4. Which principle ensures information has not been improperly
altered?
A. Integrity
B. Availability
C. Confidentiality
D. Resilience
Answer: A
Rationale: Integrity protects information from unauthorized or
improper modification.
5. Availability means that information should be:
A. Encrypted at all times
B. Accessible when authorized users need it
C. Available to everyone
D. Stored only offline
Answer: B
Rationale: Availability ensures authorized users can access systems and
information when required.
6. What is a security control?
A. A database record
B. A safeguard used to manage risk
C. A programming language
D. A network cable
Answer: B
,Rationale: Security controls are measures designed to prevent, detect,
correct, or reduce security risks.
7. Which is an example of a preventive control?
A. Security incident report
B. Firewall rule
C. Post-incident review
D. Audit finding
Answer: B
Rationale: Firewalls can prevent unauthorized network traffic from
reaching protected systems.
8. Which control is primarily detective?
A. Intrusion detection system
B. Password policy
C. Encryption
D. Network segmentation
Answer: A
Rationale: An IDS detects and alerts on potentially malicious activity.
9. Which is a corrective control?
A. Backup restoration after data loss
B. Password complexity requirement
C. Security awareness training
D. Firewall filtering
Answer: A
Rationale: Corrective controls restore systems or reduce the effects of
an incident.
10. What does defense in depth mean?
A. Using one very strong control
, B. Using multiple layers of security controls
C. Removing redundant controls
D. Outsourcing security
Answer: B
Rationale: Defense in depth uses multiple complementary controls so
failure of one does not expose the organization completely.
11. What is the principle of least privilege?
A. Users receive administrator privileges by default
B. Users receive only the access necessary to perform their duties
C. Everyone receives identical permissions
D. Privileges never expire
Answer: B
Rationale: Least privilege reduces the potential damage caused by
misuse or compromise of an account.
12. What is separation of duties designed to prevent?
A. Network congestion
B. One individual controlling an entire sensitive process
C. Software updates
D. Data backups
Answer: B
Rationale: Separating responsibilities reduces fraud, abuse, and
unauthorized activity.
13. What does nonrepudiation provide?
A. Faster networks
B. Evidence that a party performed or approved an action
C. Unlimited access
D. Password recovery
Risks, Data Management & IT Governance
Section 1: Information Security Fundamentals
1. What is the primary objective of information security?
A. Increase internet bandwidth
B. Protect information and information systems from threats
C. Eliminate all technology costs
D. Replace business processes
Answer: B
Rationale: Information security protects information and systems
against unauthorized access, use, disclosure, disruption, modification,
or destruction.
2. Which three principles form the classic CIA triad?
A. Control, Inspection, Authorization
B. Confidentiality, Integrity, Availability
C. Compliance, Information, Authentication
D. Cybersecurity, Identification, Accountability
Answer: B
Rationale: Confidentiality, integrity, and availability are the foundational
objectives of information security.
3. Which security principle prevents unauthorized disclosure of
information?
A. Integrity
B. Availability
C. Confidentiality
,D. Nonrepudiation
Answer: C
Rationale: Confidentiality ensures information is accessible only to
authorized individuals or systems.
4. Which principle ensures information has not been improperly
altered?
A. Integrity
B. Availability
C. Confidentiality
D. Resilience
Answer: A
Rationale: Integrity protects information from unauthorized or
improper modification.
5. Availability means that information should be:
A. Encrypted at all times
B. Accessible when authorized users need it
C. Available to everyone
D. Stored only offline
Answer: B
Rationale: Availability ensures authorized users can access systems and
information when required.
6. What is a security control?
A. A database record
B. A safeguard used to manage risk
C. A programming language
D. A network cable
Answer: B
,Rationale: Security controls are measures designed to prevent, detect,
correct, or reduce security risks.
7. Which is an example of a preventive control?
A. Security incident report
B. Firewall rule
C. Post-incident review
D. Audit finding
Answer: B
Rationale: Firewalls can prevent unauthorized network traffic from
reaching protected systems.
8. Which control is primarily detective?
A. Intrusion detection system
B. Password policy
C. Encryption
D. Network segmentation
Answer: A
Rationale: An IDS detects and alerts on potentially malicious activity.
9. Which is a corrective control?
A. Backup restoration after data loss
B. Password complexity requirement
C. Security awareness training
D. Firewall filtering
Answer: A
Rationale: Corrective controls restore systems or reduce the effects of
an incident.
10. What does defense in depth mean?
A. Using one very strong control
, B. Using multiple layers of security controls
C. Removing redundant controls
D. Outsourcing security
Answer: B
Rationale: Defense in depth uses multiple complementary controls so
failure of one does not expose the organization completely.
11. What is the principle of least privilege?
A. Users receive administrator privileges by default
B. Users receive only the access necessary to perform their duties
C. Everyone receives identical permissions
D. Privileges never expire
Answer: B
Rationale: Least privilege reduces the potential damage caused by
misuse or compromise of an account.
12. What is separation of duties designed to prevent?
A. Network congestion
B. One individual controlling an entire sensitive process
C. Software updates
D. Data backups
Answer: B
Rationale: Separating responsibilities reduces fraud, abuse, and
unauthorized activity.
13. What does nonrepudiation provide?
A. Faster networks
B. Evidence that a party performed or approved an action
C. Unlimited access
D. Password recovery