Comprehensive Cybersecurity Study Guide & Exam
Preparation
Cybersecurity Fundamentals Certification Examination
Core Domains: CIA Triad & Security Principles · Risk Management & Threat Modeling · Network Security
Fundamentals · Cryptography & PKI Concepts · Access Control & Identity Management · Security Operations &
Incident Response · Compliance Frameworks (NIST CSF 2.0, ISO/IEC 27001, CIS Controls) · Security Awareness &
Social Engineering Defense · Vulnerability Assessment & Penetration Testing Basics · Legal and Ethical
Considerations in Cybersecurity
Entry-Level Security Professional Focus | Multiple-Choice, Multiple-Select, Drag-and-Drop, Performance-
Based & Scenario Analysis Format
Examination length 75 questions
Time limit 2 hours (120 minutes)
Delivery Proctored online assessment
Item formats Multiple-choice · multiple-select · drag-and-drop · performance-based
Blueprint alignment GIAC Information Security Fundamentals (GISF) and ISACA Cybersecurity
Fundamentals exam blueprints
Normative baseline NIST CSF 2.0 · NIST SP 800-53 Rev. 5.2.0 · NIST SP 800-61r3 · ISO/IEC 27001:2022
(+ Amd 1:2024) · CIS Controls v8.1 · NIST SP 800-63-4
Items in this guide 75 examination items with answer key, rationales and 10 labelled figures
How to Use This Guide
Each of the 75 items below is presented in examination form, followed immediately by the verified
answer and a rationale. Correct answers are rendered in bold green so that the answer key can be
located at a glance; rationales are set in italic and cite the controlling standard, publication or statute.
Work each item under timed conditions before reading the answer — the rationale is written to
explain why the distractors fail as well as why the key is correct, which is where most of the learning
value sits.
Answer format legend: Correct Answer (bold, green) · Rationale and analysis (italic) · References
(small caps citation line)
Fundamentals of Information Security · Study Guide 2026/2027 · Page 1
,Introduction
This Fundamentals of Information Security Study Guide for the 2026/2027 update prepares entry-
level cybersecurity professionals on the foundational principles, technical controls, and governance
frameworks essential to protecting information assets. The content emphasises threat identification,
risk mitigation strategies, secure configuration standards, and regulatory compliance aligned with the
NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and industry best practice, ensuring
learners can analyse security scenarios, apply defense-in-depth principles, and demonstrate
competency in the core cybersecurity domains required for certification and workforce readiness.
The 2026/2027 cycle differs materially from earlier editions, and candidates preparing from older
material will encounter superseded content. Four changes matter most. First, NIST SP 800-61 Revision
3, finalised in April 2025, retired the familiar four-phase incident response model and recast incident
response as a CSF 2.0 Community Profile spanning all six Functions. Second, the ISO/IEC 27001:2013
transition period closed on 31 October 2025, so the 93-control, four-theme Annex A of the 2022
edition — together with the 2024 climate action amendment to Clauses 4.1 and 4.2 — is now the only
valid structure. Third, NIST finalised SP 800-63-4 in August 2025, tightening the assurance-level
requirements for identity proofing, authentication and federation. Fourth, the post-quantum standards
FIPS 203, 204 and 205 are final and migration guidance is examinable, while HQC remains a selected
but not-yet-final backup mechanism.
Items are distributed across ten domains in proportion to their weight in the published blueprints.
Nine performance-based items and two drag-and-drop items are included because these formats carry
disproportionate marks and are the ones candidates most often under-prepare for; their model
answers include the grading logic examiners apply, not merely a correct response.
Domain Weighting and Item Distribution
Domain Focus area Items Figures
Domain 1 CIA Triad and Core Security Principles 1–8 (8) 1, 2
Domain 2 Risk Management and Threat Modeling 9–16 (8) 7
Domain 3 Network Security Fundamentals 17–25 (9) 3
Domain 4 Cryptography and PKI Concepts 26–34 (9) 4, 9
Domain 5 Access Control and Identity Management 35–42 (8) 8
Domain 6 Security Operations and Incident Response 43–50 (8) 6, 10
Domain 7 Compliance Frameworks (NIST CSF 2.0, ISO/IEC 27001, CIS 51–58 (8) 5
Controls)
Domain 8 Security Awareness and Social Engineering Defense 59–63 (5) —
Domain 9 Vulnerability Assessment and Penetration Testing Basics 64–70 (7) —
Domain 10 Legal and Ethical Considerations in Cybersecurity 71–75 (5) —
Fundamentals of Information Security · Study Guide 2026/2027 · Page 2
,Part I — Core Concepts and Reference Architectures
The ten figures in this guide are examinable in their own right. Performance-based items routinely
present a topology or process diagram and ask the candidate to locate a control, identify a flaw, or
justify a placement decision. Study each figure until you can redraw it from memory and explain the
security purpose of every element it contains.
Figure 1. The CIA triad and its supporting security properties. Confidentiality, integrity and availability are the three
objectives against which every control is justified; authenticity, non-repudiation, possession and utility extend the model
into the Parkerian Hexad.
Every examination item in Domain 1 reduces to a single question: which property was lost, and which
control function restores it? Candidates who internalise the triad as a classification instrument rather
than a slogan answer these items quickly and correctly.
Fundamentals of Information Security · Study Guide 2026/2027 · Page 3
, Figure 2. Defense-in-depth layered control architecture, showing the seven concentric control layers and the six control
functions by which individual safeguards are classified.
Defense in depth assumes that any single control will eventually fail. The design objective is therefore
not perfection at one layer but independence between layers, so that the compromise of one does not
imply the compromise of the next. Note the distinction the examination draws between control
function — preventive, detective, corrective, deterrent, compensating, directive — and control type,
which describes implementation as administrative, technical or physical. A single safeguard has both
attributes.
Fundamentals of Information Security · Study Guide 2026/2027 · Page 4