INFRASTRUCTURE PROTECTION
PLAN EXAM QUESTIONS AND
DETAILED SOLUTIONS JUST
IS-860.C - THE NATIONAL INFRASTRUCTURE PROTECTION
PLAN | Comprehensive Examination
IS-860.C - THE NATIONAL INFRASTRUCTURE
PROTECTION PLAN EXAM QUESTIONS AND
DETAILED SOLUTIONS JUST RELEASED.pdf actual exam
INTRODUCTION
This document is an important and very helpful preparation
resource for IS-860.C - THE NATIONAL INFRASTRUCTURE
PROTECTION PLAN EXAM QUESTIONS AND DETAILED
SOLUTIONS JUST RELEASED.pdf. Every item uses a focused
exam stem, four response options, a keyed response, and a clear
rationale, making it easier to understand the subject, spot
distractors, and build real exam confidence.
Page 1
, Question 1
Under the NIPP Risk Management Framework, which activity most directly
informs the prioritization of critical infrastructure for protection and resilience
investments?
A. Conducting a sector-wide vulnerability assessment without
considering threat or consequence
B. Performing a risk assessment that integrates threat, vulnerability, and
consequence
C. Implementing protective measures based solely on historical incident
frequency
D. Allocating resources equally across all 16 critical infrastructure sectors
Correct Answer: B - Performing a risk assessment that integrates
threat, vulnerability, and consequence
RATIONALE
The NIPP Risk Management Framework defines risk as a function of
threat, vulnerability, and consequence. Integrating all three allows for
risk-informed prioritization. Options A and C omit key components,
and D ignores risk-based decision-making.
Question 2
Which statement best captures the primary purpose of the National Critical
Functions (NCF) construct introduced by CISA?
A. To replace the 16 critical infrastructure sectors with a function-based
approach for risk management
B. To identify and prioritize functions so critical that their disruption
would cause national or regional catastrophic consequences
C. To assign sole responsibility for critical infrastructure protection to the
federal government
D. To create a list of specific assets that must be federally protected at all
costs
Page 2
,Correct Answer: B - To identify and prioritize functions so
critical that their disruption would cause national or regional
catastrophic consequences
RATIONALE
NCFs focus on functions-not sectors or assets-whose disruption would
have national or regional catastrophic effects. They complement, not
replace, the sector construct, and do not assign sole federal
responsibility or list specific assets.
Question 3
In the context of public-private partnerships under the NIPP, which mechanism
is specifically designed to enable voluntary, bi-directional information sharing
between the government and private sector entities?
A. Sector Coordinating Councils (SCCs)
B. Information Sharing and Analysis Centers (ISACs)
C. Government Coordinating Councils (GCCs)
D. Federal Senior Leadership Council (FSLC)
Correct Answer: B - Information Sharing and Analysis Centers
(ISACs)
RATIONALE
ISACs are private sector-led entities that facilitate bi-directional
information sharing. SCCs and GCCs are coordination bodies, and the
FSLC is an internal federal coordination body.
Question 4
Which legal authority provides the foundational basis for the Department of
Homeland Security to coordinate critical infrastructure protection efforts across
sectors?
A. Homeland Security Act of 2002, as amended
B. Posse Comitatus Act
Page 3
, C. Freedom of Information Act
D. Federal Advisory Committee Act
Correct Answer: A - Homeland Security Act of 2002, as amended
RATIONALE
The Homeland Security Act of 2002 established DHS and assigned it
critical infrastructure protection responsibilities. The other laws
govern military involvement, information disclosure, and advisory
committees, respectively.
Question 5
Which of the following best describes the role of the Critical Infrastructure
Partnership Advisory Council (CIPAC) under the NIPP?
A. To provide a forum for government and private sector partners to
collaborate on critical infrastructure protection without violating FACA
B. To enforce mandatory cybersecurity standards across all critical
infrastructure sectors
C. To conduct independent audits of private sector security practices
D. To serve as the primary intelligence-sharing hub for classified threat
information
Correct Answer: A - To provide a forum for government and
private sector partners to collaborate on critical infrastructure
protection without violating FACA
RATIONALE
CIPAC was established to facilitate government-private sector
collaboration while exempting it from FACA requirements. It does not
enforce standards, conduct audits, or serve as an intelligence hub.
Page 4