Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 124 pages
Exam (elaborations)

CITP Certification Exam Prep 2026/2027 | Cybersecurity, Data Analytics, IT Governance, Risk & Controls

Document preview thumbnail
Preview 4 out of 124 pages

CITP Certification Exam Prep 2026/2027 | Cybersecurity, Data Analytics, IT Governance, Risk & Controls

Content preview

CITP Certification Exam Prep 2026/2027 | Cybersecurity, Data
Analytics, IT Governance, Risk & Controls


SECTION 1 — INFORMATION SECURITY GOVERNANCE
Questions 1–35
Question 1
What is the primary objective of information security governance?
A. To eliminate all cybersecurity risks
B. To align security activities with organizational objectives and risk
appetite
C. To replace internal audit activities
D. To maximize technology spending
Answer: B
Explanation: Information security governance establishes direction and
accountability so security supports business objectives while managing
risk within the organization's risk appetite.
Question 2
Which document normally establishes senior management's overall
direction for information security?
A. Security policy
B. Incident ticket
C. Backup log
D. Network diagram
Answer: A

,Explanation: A security policy establishes management's high-level
expectations, objectives, responsibilities, and direction for protecting
information assets.
Question 3
Who should ultimately be accountable for an organization's information
security governance?
A. Only the network administrator
B. Senior management and the board
C. External vendors
D. Individual end users
Answer: B
Explanation: Security governance is an organizational responsibility
requiring oversight from senior management and, where appropriate,
the board.
Question 4
What is the best reason to define a security risk appetite?
A. To guarantee that no security incidents occur
B. To establish the amount and type of risk the organization is willing to
accept
C. To eliminate the need for risk assessments
D. To determine employee salaries
Answer: B
Explanation: Risk appetite provides boundaries for decision-making and
helps management determine whether identified risks require
treatment or can be accepted.

,Question 5
Which principle requires security responsibilities to be assigned clearly
to specific individuals?
A. Accountability
B. Redundancy
C. Compression
D. Encryption
Answer: A
Explanation: Accountability ensures that individuals or functions are
responsible for security decisions, controls, and outcomes.
Question 6
An organization is implementing a new cloud application. What should
occur before approving the implementation?
A. Disable all security controls
B. Perform an appropriate risk assessment
C. Delete existing policies
D. Give all users administrative privileges
Answer: B
Explanation: A risk assessment identifies threats, vulnerabilities,
potential impacts, and required controls before a significant technology
decision is approved.
Question 7
Which factor should most influence the prioritization of information-
security investments?

, A. Vendor popularity
B. Risk to critical business objectives
C. Number of employees in IT
D. Age of the organization's website
Answer: B
Explanation: Security investments should be prioritized according to
business impact, likelihood, risk exposure, and organizational
objectives.
Question 8
What is the purpose of a data classification scheme?
A. To determine employee bonuses
B. To assign appropriate protection requirements based on information
sensitivity
C. To increase storage capacity
D. To eliminate backups
Answer: B
Explanation: Classification allows organizations to apply protection
proportional to the sensitivity, confidentiality, integrity, and business
value of information.
Question 9
Which classification would generally require the strongest protection?
A. Public
B. Internal
C. Confidential or highly restricted
D. Marketing material

Document information

Uploaded on
September 15, 2026
Number of pages
124
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(24)
Sold
113
Followers
3
Items
8661
Last sold
17 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions