CITP Practice Exam 2026/2027 | 300+ Questions, Correct
Answers & Detailed Rationales | AICPA
Section 1: Information Security Governance — Questions 1–35
Q1. What is the primary objective of information security governance?
A. Eliminate every cybersecurity threat
B. Align information security with organizational objectives and risk
tolerance
C. Increase the number of security tools
D. Prevent employees from accessing technology
Answer: B
Rationale: Information security governance ensures security objectives
support business strategy while risks remain within approved tolerance.
Q2. Which principle requires users to receive only the access necessary
to perform assigned duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Availability
Answer: C
Rationale: Least privilege limits access rights to what is necessary,
reducing the potential impact of compromised or misused accounts.
,Q3. A board asks management to establish an acceptable level of
cybersecurity exposure. What concept is being defined?
A. Risk appetite
B. Data classification
C. System availability
D. Control deficiency
Answer: A
Rationale: Risk appetite represents the amount and type of risk an
organization is willing to accept in pursuing its objectives.
Q4. Which document normally establishes management's expectations
regarding acceptable use of company technology?
A. Incident log
B. Acceptable use policy
C. Backup schedule
D. Network diagram
Answer: B
Rationale: An acceptable use policy defines permitted and prohibited
uses of organizational technology and information resources.
Q5. Which activity is most important before implementing a major
information security control?
A. Purchase the most expensive security software
B. Identify the business risk the control is intended to address
,C. Disable all remote access
D. Increase password length indefinitely
Answer: B
Rationale: Controls should be risk-based. Understanding the underlying
risk helps determine whether a control is appropriate and
proportionate.
Q6. What is the primary purpose of security awareness training?
A. Replace technical security controls
B. Ensure employees understand their security responsibilities
C. Eliminate all cyberattacks
D. Automate vulnerability management
Answer: B
Rationale: Employees are part of the organization's security
environment, so awareness training helps reduce human-related
security risks.
Q7. Which control best prevents one employee from initiating and
approving the same high-value payment?
A. Encryption
B. Segregation of duties
C. Hashing
D. Network segmentation
Answer: B
Rationale: Segregation of duties divides incompatible responsibilities so
, one individual cannot complete an entire sensitive transaction
independently.
Q8. An organization classifies information as public, internal,
confidential, and restricted. What is the primary purpose?
A. Improve processor speed
B. Determine appropriate handling and protection requirements
C. Eliminate data backups
D. Increase storage capacity
Answer: B
Rationale: Data classification allows security measures to be matched
to the sensitivity and business value of information.
Q9. Which governance body would generally have the highest
responsibility for oversight of enterprise-level cybersecurity risk?
A. Help desk
B. Board or governing body
C. Individual employees
D. Database administrators
Answer: B
Rationale: The board or governing body provides high-level oversight
and ensures significant technology risks receive appropriate attention.
Q10. What is the strongest reason to periodically review information
security policies?
Answers & Detailed Rationales | AICPA
Section 1: Information Security Governance — Questions 1–35
Q1. What is the primary objective of information security governance?
A. Eliminate every cybersecurity threat
B. Align information security with organizational objectives and risk
tolerance
C. Increase the number of security tools
D. Prevent employees from accessing technology
Answer: B
Rationale: Information security governance ensures security objectives
support business strategy while risks remain within approved tolerance.
Q2. Which principle requires users to receive only the access necessary
to perform assigned duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Availability
Answer: C
Rationale: Least privilege limits access rights to what is necessary,
reducing the potential impact of compromised or misused accounts.
,Q3. A board asks management to establish an acceptable level of
cybersecurity exposure. What concept is being defined?
A. Risk appetite
B. Data classification
C. System availability
D. Control deficiency
Answer: A
Rationale: Risk appetite represents the amount and type of risk an
organization is willing to accept in pursuing its objectives.
Q4. Which document normally establishes management's expectations
regarding acceptable use of company technology?
A. Incident log
B. Acceptable use policy
C. Backup schedule
D. Network diagram
Answer: B
Rationale: An acceptable use policy defines permitted and prohibited
uses of organizational technology and information resources.
Q5. Which activity is most important before implementing a major
information security control?
A. Purchase the most expensive security software
B. Identify the business risk the control is intended to address
,C. Disable all remote access
D. Increase password length indefinitely
Answer: B
Rationale: Controls should be risk-based. Understanding the underlying
risk helps determine whether a control is appropriate and
proportionate.
Q6. What is the primary purpose of security awareness training?
A. Replace technical security controls
B. Ensure employees understand their security responsibilities
C. Eliminate all cyberattacks
D. Automate vulnerability management
Answer: B
Rationale: Employees are part of the organization's security
environment, so awareness training helps reduce human-related
security risks.
Q7. Which control best prevents one employee from initiating and
approving the same high-value payment?
A. Encryption
B. Segregation of duties
C. Hashing
D. Network segmentation
Answer: B
Rationale: Segregation of duties divides incompatible responsibilities so
, one individual cannot complete an entire sensitive transaction
independently.
Q8. An organization classifies information as public, internal,
confidential, and restricted. What is the primary purpose?
A. Improve processor speed
B. Determine appropriate handling and protection requirements
C. Eliminate data backups
D. Increase storage capacity
Answer: B
Rationale: Data classification allows security measures to be matched
to the sensitivity and business value of information.
Q9. Which governance body would generally have the highest
responsibility for oversight of enterprise-level cybersecurity risk?
A. Help desk
B. Board or governing body
C. Individual employees
D. Database administrators
Answer: B
Rationale: The board or governing body provides high-level oversight
and ensures significant technology risks receive appropriate attention.
Q10. What is the strongest reason to periodically review information
security policies?