Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 121 pages
Exam (elaborations)

CITP Practice Exam 2026/2027 | 300+ Questions, Correct Answers & Detailed Rationales | AICPA

Document preview thumbnail
Preview 4 out of 121 pages

CITP Practice Exam 2026/2027 | 300+ Questions, Correct Answers & Detailed Rationales | AICPA

Content preview

CITP Practice Exam 2026/2027 | 300+ Questions, Correct
Answers & Detailed Rationales | AICPA


Section 1: Information Security Governance — Questions 1–35
Q1. What is the primary objective of information security governance?
A. Eliminate every cybersecurity threat
B. Align information security with organizational objectives and risk
tolerance
C. Increase the number of security tools
D. Prevent employees from accessing technology
Answer: B
Rationale: Information security governance ensures security objectives
support business strategy while risks remain within approved tolerance.


Q2. Which principle requires users to receive only the access necessary
to perform assigned duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Availability
Answer: C
Rationale: Least privilege limits access rights to what is necessary,
reducing the potential impact of compromised or misused accounts.

,Q3. A board asks management to establish an acceptable level of
cybersecurity exposure. What concept is being defined?
A. Risk appetite
B. Data classification
C. System availability
D. Control deficiency
Answer: A
Rationale: Risk appetite represents the amount and type of risk an
organization is willing to accept in pursuing its objectives.


Q4. Which document normally establishes management's expectations
regarding acceptable use of company technology?
A. Incident log
B. Acceptable use policy
C. Backup schedule
D. Network diagram
Answer: B
Rationale: An acceptable use policy defines permitted and prohibited
uses of organizational technology and information resources.


Q5. Which activity is most important before implementing a major
information security control?
A. Purchase the most expensive security software
B. Identify the business risk the control is intended to address

,C. Disable all remote access
D. Increase password length indefinitely
Answer: B
Rationale: Controls should be risk-based. Understanding the underlying
risk helps determine whether a control is appropriate and
proportionate.


Q6. What is the primary purpose of security awareness training?
A. Replace technical security controls
B. Ensure employees understand their security responsibilities
C. Eliminate all cyberattacks
D. Automate vulnerability management
Answer: B
Rationale: Employees are part of the organization's security
environment, so awareness training helps reduce human-related
security risks.


Q7. Which control best prevents one employee from initiating and
approving the same high-value payment?
A. Encryption
B. Segregation of duties
C. Hashing
D. Network segmentation
Answer: B
Rationale: Segregation of duties divides incompatible responsibilities so

, one individual cannot complete an entire sensitive transaction
independently.


Q8. An organization classifies information as public, internal,
confidential, and restricted. What is the primary purpose?
A. Improve processor speed
B. Determine appropriate handling and protection requirements
C. Eliminate data backups
D. Increase storage capacity
Answer: B
Rationale: Data classification allows security measures to be matched
to the sensitivity and business value of information.


Q9. Which governance body would generally have the highest
responsibility for oversight of enterprise-level cybersecurity risk?
A. Help desk
B. Board or governing body
C. Individual employees
D. Database administrators
Answer: B
Rationale: The board or governing body provides high-level oversight
and ensures significant technology risks receive appropriate attention.


Q10. What is the strongest reason to periodically review information
security policies?

Document information

Uploaded on
September 15, 2026
Number of pages
121
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(24)
Sold
113
Followers
3
Items
8668
Last sold
19 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions