Examination 2026
Original Questions with
Verified Answers and Detailed
Rationales
1.
A security manager is developing an enterprise security
program. Senior leadership wants the program to support
organizational objectives rather than operate as an isolated
technical function. What should the security manager establish
FIRST?
,A. A vulnerability scanning schedule
B. A security awareness campaign
C. Alignment between security objectives and business
objectives
D. A penetration-testing methodology
Answer: C
Rationale: Security exists to enable and protect business
objectives. Establishing alignment with organizational goals
ensures that security investments, controls, risk decisions, and
priorities support the enterprise's mission. Technical activities
such as vulnerability scanning and penetration testing are
important, but they should follow strategic alignment rather
than define it.
2.
A company identifies a risk that could significantly affect its
operations but determines that implementing a proposed
,control would cost more than the expected loss. Which risk
treatment is MOST appropriate?
A. Risk avoidance
B. Risk transfer
C. Risk mitigation
D. Risk acceptance
Answer: D
Rationale: Risk acceptance is appropriate when management
knowingly retains a risk because the cost of additional
treatment is disproportionate to the expected benefit or
otherwise falls within the organization's risk tolerance.
Acceptance must be an informed management decision rather
than an undocumented failure to act.
3.
Who ultimately has the authority to accept an organizational
risk?
, A. Security analyst
B. System administrator
C. Security architect
D. Appropriate business or risk owner
Answer: D
Rationale: Risk ownership belongs to the person accountable for
the business process, asset, or outcome affected by the risk.
Security professionals advise and recommend controls, but they
generally do not have authority to accept business risk on behalf
of management.
4.
A company is establishing a policy requiring employees to
protect confidential information. Which statement BEST
describes the purpose of a security policy?
A. To specify individual firewall rules
B. To provide detailed configuration commands
C. To establish management's security expectations and