Plan | Exam Questions with Answer Explanations
(2026/2027 Edition)
Total Questions: 50 | Time: 90 min | Pass: 80%
TABLE OF CONTENTS
Section 1 | Risk Assessment & Asset Identification | Q1 – Q10
Section 2 | Security Controls & Frameworks (NIST CSF) | Q11 – Q20
Section 3 | Incident Response & Recovery Planning | Q21 – Q30
Section 4 | Policy Development & Compliance | Q31 – Q40
Section 5 | Business Continuity & Disaster Recovery | Q41 – Q50
Instructions: Choose the single best answer. Pass: 80% in 90 minutes.
══════════════════════════════════════
SECTION 1: RISK ASSESSMENT & ASSET IDENTIFICATION Q1 – Q10
══════════════════════════════════════
Question 1 of 50
A 42-year-old CISO at a mid-sized regional bank has been asked to conduct a
comprehensive risk assessment before the bank migrates its core banking platform to
the cloud. During the asset inventory phase, she discovers that several departments
maintain shadow IT spreadsheets on personal drives, and no one has updated the
official asset register in 14 months. She needs to establish a baseline that will feed
directly into the risk register.
A. Proceed immediately to threat modeling using the outdated asset register to save
time.
B. First conduct a thorough asset discovery and validation process, then classify assets
by criticality before moving to threat identification. ✓ CORRECT
C. Skip the asset inventory and focus exclusively on cloud provider security
certifications.
,D. Delegate the entire risk assessment to the cloud vendor since they own the
infrastructure.
Correct Answer: B
Rationale: A valid risk assessment requires accurate, current asset data as its
foundation; without knowing what you have and how critical it is, threat and vulnerability
analysis becomes guesswork. Option A is tempting because teams often feel pressure
to accelerate, but using stale data produces a false sense of security and misallocates
controls. In practice, most auditors will halt an assessment if the asset inventory cannot
be reconciled.
Question 2 of 50
A 35-year-old IT director at a 400-bed hospital is preparing for an annual HIPAA security
risk analysis. The hospital recently merged with two smaller clinics, and the new
equipment lists, software licenses, and medical device inventories have never been
consolidated. Leadership wants the risk analysis completed within 30 days to meet an
audit deadline.
A. Merge the three inventories into a single authoritative asset inventory, then apply a
criticality matrix based on patient safety impact, data sensitivity, and operational
dependency. ✓ CORRECT
B. Run the risk analysis on the original hospital only and plan to address the clinics next
year.
C. Estimate the clinic asset counts and extrapolate risk scores from the main hospital
data.
D. Outsource the inventory merge to a temp agency and proceed with the risk analysis
immediately.
Correct Answer: A
Rationale: Post-merger environments are high-risk precisely because asset visibility
breaks down, so consolidation and criticality ranking must precede any meaningful risk
scoring. Option B is a common leadership shortcut, but auditors and regulators expect
,the entire covered entity to be in scope. Many healthcare breaches trace back to
forgotten systems from acquired sites that were never inventoried.
Question 3 of 50
A 51-year-old risk manager at a manufacturing firm with 2,800 employees is reviewing
the results of a recent penetration test. The report shows that the engineering
department's legacy CAD server, which hosts proprietary designs, is running an
unsupported operating system and is directly accessible from the guest Wi-Fi network.
The risk manager needs to present this to the board with a clear prioritization rationale.
A. Rank this risk low because the server is internal and requires no immediate action.
B. Report the finding as informational only since the data is not customer-facing.
C. Classify the risk as critical due to the combination of high-value intellectual property,
unsupported software, and network segmentation failure, and recommend immediate
containment. ✓ CORRECT
D. Wait for the next annual vulnerability scan before raising the issue to avoid alarm.
Correct Answer: C
Rationale: Risk prioritization should account for asset value, threat exposure, and
vulnerability severity together; this scenario hits all three markers at extreme levels.
Option A represents a dangerous assumption that internal assets are safe, which is
exactly how lateral movement begins after an initial compromise. Manufacturing firms
lose billions annually to intellectual property theft from exactly this type of overlooked
legacy system.
Question 4 of 50
A 29-year-old security analyst at a rapidly growing e-commerce startup has been tasked
with building a threat model for the company's new mobile payment application. The
startup processes 50,000 transactions daily and stores encrypted payment card data.
, The development team is using Agile sprints and wants security feedback integrated
without slowing releases.
A. Delay threat modeling until after the application launches to avoid disrupting the
sprint schedule.
B. Use STRIDE exclusively because it is the only framework suitable for payment
applications.
C. Implement threat modeling during design and sprint planning using a lightweight
framework like STRIDE or PASTA, focusing on data flow diagrams and attack surfaces
tied to payment processing. ✓ CORRECT
D. Rely on the payment processor's security team to handle all threat modeling for the
startup.
Correct Answer: C
Rationale: Effective threat modeling is most valuable when embedded early in the
development lifecycle, and lightweight frameworks can keep pace with Agile without
becoming bureaucratic. Option B is incorrect because no single framework is
universally mandated; the best choice depends on organizational maturity and specific
threat landscapes. Startups that embed threat modeling early typically reduce
remediation costs by an order of magnitude compared to post-launch fixes.
Question 5 of 50
A 47-year-old CIO at a state university is reviewing the institution's risk register after a
recent internal audit flagged 73 open risks with no assigned owners. The university
maintains sensitive student records, research data, and critical infrastructure for a
30,000-student population. The audit found that risks were being logged but never
scored, and mitigation timelines were missing.
A. Close all risks older than six months to clean up the register and start fresh.
B. Rebuild the register by assigning each risk an owner, applying a consistent qualitative
or quantitative scoring methodology, and establishing realistic mitigation timelines with
executive accountability. ✓ CORRECT