Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 104 pages
Exam (elaborations)

IS 860.C THE NATIONAL INFRASTRUCTURE PROTECTION PLAN EXAM QUESTIONS AND DETAILED SOLUTIONS JUST RELEASED| INSTANT DOWNLOAD

Document preview thumbnail
Preview 4 out of 104 pages

This study guide covers the IS-860.C National Infrastructure Protection Plan exam with practice questions and detailed answer explanations. Topics include the NIPP Risk Management Framework, National Critical Functions, public-private partnerships, ISACs, GCCs, SCCs, CIPAC, cross-sector dependencies, PPD-41 significant cyber incidents, and shared responsibility. Each question includes four options, the correct answer, and a rationale to help you understand the material and prepare for the real exam.

Content preview

IS-860.C - THE NATIONAL
INFRASTRUCTURE PROTECTION
PLAN EXAM QUESTIONS AND
DETAILED SOLUTIONS JUST
IS-860.C - THE NATIONAL INFRASTRUCTURE PROTECTION
PLAN | Comprehensive Examination
IS-860.C - THE NATIONAL INFRASTRUCTURE
PROTECTION PLAN EXAM QUESTIONS AND
DETAILED SOLUTIONS JUST RELEASED.pdf actual exam




INTRODUCTION
This document is an important and very helpful preparation
resource for IS-860.C - THE NATIONAL INFRASTRUCTURE
PROTECTION PLAN EXAM QUESTIONS AND DETAILED
SOLUTIONS JUST RELEASED.pdf. Every item uses a focused
exam stem, four response options, a keyed response, and a clear
rationale, making it easier to understand the subject, spot
distractors, and build real exam confidence.




Page 1

, Question 1
Under the NIPP Risk Management Framework, which activity most directly
informs the prioritization of critical infrastructure for protection and resilience
investments?
A. Conducting a sector-wide vulnerability assessment without
considering threat or consequence
B. Performing a risk assessment that integrates threat, vulnerability, and
consequence
C. Implementing protective measures based solely on historical incident
frequency
D. Allocating resources equally across all 16 critical infrastructure sectors
Correct Answer: B - Performing a risk assessment that integrates
threat, vulnerability, and consequence


RATIONALE
The NIPP Risk Management Framework defines risk as a function of
threat, vulnerability, and consequence. Integrating all three allows for
risk-informed prioritization. Options A and C omit key components,
and D ignores risk-based decision-making.

Question 2
Which statement best captures the primary purpose of the National Critical
Functions (NCF) construct introduced by CISA?
A. To replace the 16 critical infrastructure sectors with a function-based
approach for risk management
B. To identify and prioritize functions so critical that their disruption
would cause national or regional catastrophic consequences
C. To assign sole responsibility for critical infrastructure protection to the
federal government
D. To create a list of specific assets that must be federally protected at all
costs


Page 2

,Correct Answer: B - To identify and prioritize functions so

critical that their disruption would cause national or regional

catastrophic consequences




RATIONALE
NCFs focus on functions-not sectors or assets-whose disruption would
have national or regional catastrophic effects. They complement, not
replace, the sector construct, and do not assign sole federal
responsibility or list specific assets.

Question 3
In the context of public-private partnerships under the NIPP, which mechanism
is specifically designed to enable voluntary, bi-directional information sharing
between the government and private sector entities?
A. Sector Coordinating Councils (SCCs)
B. Information Sharing and Analysis Centers (ISACs)
C. Government Coordinating Councils (GCCs)
D. Federal Senior Leadership Council (FSLC)
Correct Answer: B - Information Sharing and Analysis Centers
(ISACs)


RATIONALE
ISACs are private sector-led entities that facilitate bi-directional
information sharing. SCCs and GCCs are coordination bodies, and the
FSLC is an internal federal coordination body.

Question 4
Which legal authority provides the foundational basis for the Department of
Homeland Security to coordinate critical infrastructure protection efforts across
sectors?
A. Homeland Security Act of 2002, as amended
B. Posse Comitatus Act


Page 3

, C. Freedom of Information Act

D. Federal Advisory Committee Act
Correct Answer: A - Homeland Security Act of 2002, as amended


RATIONALE
The Homeland Security Act of 2002 established DHS and assigned it
critical infrastructure protection responsibilities. The other laws
govern military involvement, information disclosure, and advisory
committees, respectively.

Question 5
Which of the following best describes the role of the Critical Infrastructure
Partnership Advisory Council (CIPAC) under the NIPP?
A. To provide a forum for government and private sector partners to
collaborate on critical infrastructure protection without violating FACA
B. To enforce mandatory cybersecurity standards across all critical
infrastructure sectors
C. To conduct independent audits of private sector security practices
D. To serve as the primary intelligence-sharing hub for classified threat
information
Correct Answer: A - To provide a forum for government and
private sector partners to collaborate on critical infrastructure
protection without violating FACA


RATIONALE
CIPAC was established to facilitate government-private sector
collaboration while exempting it from FACA requirements. It does not
enforce standards, conduct audits, or serve as an intelligence hub.




Page 4

Document information

Uploaded on
September 21, 2026
Number of pages
104
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
£23.16

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
GoldenExams
4.5
(67)
Sold
34
Followers
17
Items
6372
Last sold
1 hour ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions