Exam 2026/2027 – Complete Exam-Style Questions with
Detailed Rationales | 100% Verified | Pass Guaranteed – A+
Graded
Section A: Cybersecurity Governance, Risk Management, &
Compliance
Q1: A healthcare organization's CISO is implementing the NIST Cybersecurity
Framework to improve security operations. The team is currently inventorying hardware
assets, identifying data flows, and assessing organizational risk. Which NIST CSF Core
function best describes these activities?
A. Protect
B. Detect
C. Identify [CORRECT]
D. Respond
Correct Answer: C
Rationale: The Identify function encompasses asset management, risk assessment, and
understanding the business environment. Options A involves safeguards, B involves
anomaly detection, and D involves incident response actions.
Q2: An organization is selecting security controls from NIST SP 800-53 for a new federal
information system. A firewall restricting network traffic based on predefined rules is
best classified as which type of security control?
,A. Administrative control
B. Physical control
C. Technical control [CORRECT]
D. Compensating control
Correct Answer: C
Rationale: Firewalls are technical (logical) controls implemented through hardware or
software. Option A involves policies and procedures, Option B involves physical barriers,
and Option D is an alternative control used when primary controls are not feasible.
Q3: A hospital's cybersecurity team must ensure the protection of patient health
information. Which regulatory framework imposes specific security and privacy
requirements on this organization?
A. PCI DSS
B. SOX
C. HIPAA [CORRECT]
D. GLBA
Correct Answer: C
Rationale: HIPAA establishes security and privacy requirements for protected health
information (PHI). Option A governs payment card data, Option B governs financial
reporting, and Option D governs financial institution customer data.
,Q4: During a risk assessment, a security analyst has identified threats and
vulnerabilities affecting the organization's ERP system. What is the next step in the risk
management process?
A. Immediately eliminate all identified risks.
B. Risk analysis and evaluation to determine likelihood and impact. [CORRECT]
C. Purchase cyber insurance without further analysis.
D. Notify all customers of a potential data breach.
Correct Answer: B
Rationale: After risk identification, the standard process involves analyzing and
evaluating risks to determine their significance before selecting treatment options.
Option A is impractical, Option C bypasses analysis, and Option D is premature without
confirmed compromise.
Q5: Following a ransomware attack, an organization restores critical systems from
clean backups to resume operations. The backup restoration capability functions as
which type of security control?
A. Preventive control
B. Detective control
C. Corrective control [CORRECT]
D. Deterrent control
Correct Answer: C
, Rationale: Corrective controls restore systems or data after an incident. Option A blocks
incidents before they occur, Option B identifies incidents, and Option D discourages
malicious activity.
Q6: An organization is developing its security documentation hierarchy. Which
document type establishes mandatory, specific requirements that must be followed?
A. Policy
B. Standard [CORRECT]
C. Guideline
D. Baseline
Correct Answer: B
Rationale: Standards are mandatory, specific requirements. Option A is a high-level
statement of intent, Option C is advisory, and Option D is a minimum security
configuration.
Q7: A publicly traded company must demonstrate that its financial data integrity
controls are effective. Which compliance requirement drives this need?
A. GDPR
B. PCI DSS
C. SOX [CORRECT]
D. FERPA