CITP Certification Exam Prep 2026/2027 | Cybersecurity, Data
Analytics, IT Governance, Risk & Controls
SECTION 1 — INFORMATION SECURITY GOVERNANCE
Questions 1–35
Question 1
What is the primary objective of information security governance?
A. To eliminate all cybersecurity risks
B. To align security activities with organizational objectives and risk
appetite
C. To replace internal audit activities
D. To maximize technology spending
Answer: B
Explanation: Information security governance establishes direction and
accountability so security supports business objectives while managing
risk within the organization's risk appetite.
Question 2
Which document normally establishes senior management's overall
direction for information security?
A. Security policy
B. Incident ticket
C. Backup log
D. Network diagram
Answer: A
,Explanation: A security policy establishes management's high-level
expectations, objectives, responsibilities, and direction for protecting
information assets.
Question 3
Who should ultimately be accountable for an organization's information
security governance?
A. Only the network administrator
B. Senior management and the board
C. External vendors
D. Individual end users
Answer: B
Explanation: Security governance is an organizational responsibility
requiring oversight from senior management and, where appropriate,
the board.
Question 4
What is the best reason to define a security risk appetite?
A. To guarantee that no security incidents occur
B. To establish the amount and type of risk the organization is willing to
accept
C. To eliminate the need for risk assessments
D. To determine employee salaries
Answer: B
Explanation: Risk appetite provides boundaries for decision-making and
helps management determine whether identified risks require
treatment or can be accepted.
,Question 5
Which principle requires security responsibilities to be assigned clearly
to specific individuals?
A. Accountability
B. Redundancy
C. Compression
D. Encryption
Answer: A
Explanation: Accountability ensures that individuals or functions are
responsible for security decisions, controls, and outcomes.
Question 6
An organization is implementing a new cloud application. What should
occur before approving the implementation?
A. Disable all security controls
B. Perform an appropriate risk assessment
C. Delete existing policies
D. Give all users administrative privileges
Answer: B
Explanation: A risk assessment identifies threats, vulnerabilities,
potential impacts, and required controls before a significant technology
decision is approved.
Question 7
Which factor should most influence the prioritization of information-
security investments?
, A. Vendor popularity
B. Risk to critical business objectives
C. Number of employees in IT
D. Age of the organization's website
Answer: B
Explanation: Security investments should be prioritized according to
business impact, likelihood, risk exposure, and organizational
objectives.
Question 8
What is the purpose of a data classification scheme?
A. To determine employee bonuses
B. To assign appropriate protection requirements based on information
sensitivity
C. To increase storage capacity
D. To eliminate backups
Answer: B
Explanation: Classification allows organizations to apply protection
proportional to the sensitivity, confidentiality, integrity, and business
value of information.
Question 9
Which classification would generally require the strongest protection?
A. Public
B. Internal
C. Confidential or highly restricted
D. Marketing material
Analytics, IT Governance, Risk & Controls
SECTION 1 — INFORMATION SECURITY GOVERNANCE
Questions 1–35
Question 1
What is the primary objective of information security governance?
A. To eliminate all cybersecurity risks
B. To align security activities with organizational objectives and risk
appetite
C. To replace internal audit activities
D. To maximize technology spending
Answer: B
Explanation: Information security governance establishes direction and
accountability so security supports business objectives while managing
risk within the organization's risk appetite.
Question 2
Which document normally establishes senior management's overall
direction for information security?
A. Security policy
B. Incident ticket
C. Backup log
D. Network diagram
Answer: A
,Explanation: A security policy establishes management's high-level
expectations, objectives, responsibilities, and direction for protecting
information assets.
Question 3
Who should ultimately be accountable for an organization's information
security governance?
A. Only the network administrator
B. Senior management and the board
C. External vendors
D. Individual end users
Answer: B
Explanation: Security governance is an organizational responsibility
requiring oversight from senior management and, where appropriate,
the board.
Question 4
What is the best reason to define a security risk appetite?
A. To guarantee that no security incidents occur
B. To establish the amount and type of risk the organization is willing to
accept
C. To eliminate the need for risk assessments
D. To determine employee salaries
Answer: B
Explanation: Risk appetite provides boundaries for decision-making and
helps management determine whether identified risks require
treatment or can be accepted.
,Question 5
Which principle requires security responsibilities to be assigned clearly
to specific individuals?
A. Accountability
B. Redundancy
C. Compression
D. Encryption
Answer: A
Explanation: Accountability ensures that individuals or functions are
responsible for security decisions, controls, and outcomes.
Question 6
An organization is implementing a new cloud application. What should
occur before approving the implementation?
A. Disable all security controls
B. Perform an appropriate risk assessment
C. Delete existing policies
D. Give all users administrative privileges
Answer: B
Explanation: A risk assessment identifies threats, vulnerabilities,
potential impacts, and required controls before a significant technology
decision is approved.
Question 7
Which factor should most influence the prioritization of information-
security investments?
, A. Vendor popularity
B. Risk to critical business objectives
C. Number of employees in IT
D. Age of the organization's website
Answer: B
Explanation: Security investments should be prioritized according to
business impact, likelihood, risk exposure, and organizational
objectives.
Question 8
What is the purpose of a data classification scheme?
A. To determine employee bonuses
B. To assign appropriate protection requirements based on information
sensitivity
C. To increase storage capacity
D. To eliminate backups
Answer: B
Explanation: Classification allows organizations to apply protection
proportional to the sensitivity, confidentiality, integrity, and business
value of information.
Question 9
Which classification would generally require the strongest protection?
A. Public
B. Internal
C. Confidential or highly restricted
D. Marketing material