Complete Exam Questions and Answers
(2026 Edition)
A company is evaluating its risk management approach. It wants to develop a
straegy that balances between mitigating risks and exploiting opportunities
without bias toward risk avoidance or risk acceptance. Which type of risk
management strategy MOST effectively meets their needs?
- Answer-A. Neutral strategy
A company identifies a potential security risk associated with the implementation
of a new system. However, after assessing the risk, the company decides not to
implement any measures to address this specific risk. Which of the following risk
management strategy is the company employing?
- Answer-D. Exemption
Page 1 of 35
,An IT company purchases a commercial-off-the-shelf (COTS) product that allows
four developers to access and run the product against developed code for
vulnerability and threat assessments. An IT audit indicates that five developers
have accessed the product. Which of the following BEST describes what the
company has violated?
- Answer-C. Compliance/Licensing
Which of the following security actions represents a non-intrusive scanning type
of framework?
- Answer-D. Vulnerability Scanning
A cybersecurity team is investigating a complex cyber threat landscape for a large
financial institution. The team is aware of some potential threats due to previous
encounters and security measures in place, but the evolving nature of the
landscape presents new threats and challenges. What type of cyber environment
is the team dealing with?
Page 2 of 35
,- Answer-D. Partially known environment
In a large organization, the IT department is working on enhancing information
security measures. They have identified the need for stronger guidelines to
ensure the protection of sensitive data and prevent unauthorized access. As part
of their efforts, they are specifically focusing on password policies. The guidelines
aim to establish rules for creating and managing passwords effectively. The IT
team wants to strike a balance between password complexity and user
convenience to promote secure practices. They intend to enforce regular
password updates and implement measures to prevent password reuse across
multiple accounts. What is the IT department working on to ensure the protection
of sensitive data and prevent unauthorized access?
- Answer-D. Enhancing measures through stronger guidelines/password policies
A. Training employees on the basics of computer security (incorrect)
B. Developing a new IT infrastructure to support company-wide access (incorrect)
Page 3 of 35
, The IT department at a governmental agency ensures the organization's
information security. When a new employee joins or leaves the organization, the
department sets up and terminates the user accounts, grants and revokes
appropriate access permissions, and provides and collects necessary resources.
These procedures are critical for maintaining the security and integrity of the
organization's data and systems. What is one of the critical responsibilities of the
IT department related to information security in this agency?
- Answer-B. Managing employee onboarding and offboarding procedures
An organization has recently implemented new security standards as part of its
strategy to enhance its information systems security. The security team monitors
the implementation of these standards and revises them as necessary.
Considering the given scenario, what is the primary purpose of the security team
monitoring and revising the security standards?
- Answer-D. Ensuring the standards remain effective and relevant
As an integral part of compliance monitoring, what requires individuals or entities
to announce their understanding of compliance obligations formally?
Page 4 of 35