C727- Cybersecurity Management I
Exam 2026 Questions and Answers
Define security - Correct answer-The practice dealing with all aspects of
prevention, protection, and remediation from any type of harm to an asset.
Define cybersecurity - Correct answer-The ongoing application of best practices
intended to ensure and preserve confidentiality, integrity, and availability of digital
information as well as the safety of people and environments
What are the three pillars of cybersecurity?
AKA the CIA Triad. - Correct answer-Confidentiality, integrity, and availability
Define confidentiality - Correct answer-Synonymous with private or secret; seeks
to prevent the unauthorized disclosure of information.
What are the three degrees of confidentiality? - Correct answer-Top secret, secret,
and confidential
What are the degrees of harm of the confidential classifications? - Correct answer-
Exceptionally grave prejudice, serious harm, and harm
©COPYRIGHT 2025 ALL RIGHTS RESERVED 1
,Define integrity - Correct answer-The set of practices and tools (controls) designed
to protect, maintain, and ensure both the accuracy and completeness of data over
its entire life cycle.
Define availability - Correct answer-The set of practices and tools designed to
ensure timely access to data.
What are the two ways to ensure availability? - Correct answer-Redundancy and
backup
Define standards in a cybersecurity context - Correct answer-A set of properties
that something must meet to be considered appropriate to its function.
What are some of the most common cybersecurity standards? - Correct answer-
International Standards Organization (ISO), Institute of Electrical and Electronics
Engineers (IEEE) 802.3 Ethernet standard, and The National Institute of Standards
and Technology (NIST) Cybersecurity Framework (CSF)
What are the five key functions of NIST CSF? - Correct answer-Identify, protect,
detect, respond, and recover.
What is the general purpose of access security controls? - Correct answer-They are
actions that mitigate risk
©COPYRIGHT 2025 ALL RIGHTS RESERVED 2
, Define preventative controls - Correct answer-Designed to prevent the attack from
reaching the asset in the first place.
Define detective controls - Correct answer-Designed to identify that an attack is
occurring, including what kind of an attack, where it came from, what it used, and,
if you're lucky, who may be behind it.
Define corrective controls - Correct answer-Designed to minimize the damage
from an attack.
Define compensating controls - Correct answer-Designed to compensate for the
failure or absence of other controls and mitigate the damage from an attack
Define deterrent controls - Correct answer-Designed to deter users from
performing actions on a system
Define threat agents - Correct answer-The people behind cyberattacks
What motivates cybercriminals? - Correct answer-Money
What motivates insider threats? - Correct answer-Money or revenge, in no
particular order
What motivates nation-state threats? - Correct answer-Cyberwarfare or intellectual
property theft, competitive intelligence gathering, etc.
©COPYRIGHT 2025 ALL RIGHTS RESERVED 3
Exam 2026 Questions and Answers
Define security - Correct answer-The practice dealing with all aspects of
prevention, protection, and remediation from any type of harm to an asset.
Define cybersecurity - Correct answer-The ongoing application of best practices
intended to ensure and preserve confidentiality, integrity, and availability of digital
information as well as the safety of people and environments
What are the three pillars of cybersecurity?
AKA the CIA Triad. - Correct answer-Confidentiality, integrity, and availability
Define confidentiality - Correct answer-Synonymous with private or secret; seeks
to prevent the unauthorized disclosure of information.
What are the three degrees of confidentiality? - Correct answer-Top secret, secret,
and confidential
What are the degrees of harm of the confidential classifications? - Correct answer-
Exceptionally grave prejudice, serious harm, and harm
©COPYRIGHT 2025 ALL RIGHTS RESERVED 1
,Define integrity - Correct answer-The set of practices and tools (controls) designed
to protect, maintain, and ensure both the accuracy and completeness of data over
its entire life cycle.
Define availability - Correct answer-The set of practices and tools designed to
ensure timely access to data.
What are the two ways to ensure availability? - Correct answer-Redundancy and
backup
Define standards in a cybersecurity context - Correct answer-A set of properties
that something must meet to be considered appropriate to its function.
What are some of the most common cybersecurity standards? - Correct answer-
International Standards Organization (ISO), Institute of Electrical and Electronics
Engineers (IEEE) 802.3 Ethernet standard, and The National Institute of Standards
and Technology (NIST) Cybersecurity Framework (CSF)
What are the five key functions of NIST CSF? - Correct answer-Identify, protect,
detect, respond, and recover.
What is the general purpose of access security controls? - Correct answer-They are
actions that mitigate risk
©COPYRIGHT 2025 ALL RIGHTS RESERVED 2
, Define preventative controls - Correct answer-Designed to prevent the attack from
reaching the asset in the first place.
Define detective controls - Correct answer-Designed to identify that an attack is
occurring, including what kind of an attack, where it came from, what it used, and,
if you're lucky, who may be behind it.
Define corrective controls - Correct answer-Designed to minimize the damage
from an attack.
Define compensating controls - Correct answer-Designed to compensate for the
failure or absence of other controls and mitigate the damage from an attack
Define deterrent controls - Correct answer-Designed to deter users from
performing actions on a system
Define threat agents - Correct answer-The people behind cyberattacks
What motivates cybercriminals? - Correct answer-Money
What motivates insider threats? - Correct answer-Money or revenge, in no
particular order
What motivates nation-state threats? - Correct answer-Cyberwarfare or intellectual
property theft, competitive intelligence gathering, etc.
©COPYRIGHT 2025 ALL RIGHTS RESERVED 3