AND ANSWERS|2026 UPDATES|WITH
COMPLETE SOLUTION.
---
DOMAIN 1: SECURITY GOVERNANCE, RISK & COMPLIANCE (Questions 1–60)
1. Which of the following best defines the "CIA Triad" in cybersecurity?
A) Confidentiality, Integrity, Availability
B) Confidentiality, Investigation, Authorization
C) Control, Inspection, Auditing
D) Compliance, Integrity, Assessment
Answer: A
Rationale: The CIA Triad is the foundation of information security, representing
Confidentiality (preventing unauthorized access), Integrity (ensuring data
accuracy), and Availability (ensuring systems are accessible when needed).
---
2. What is the primary goal of a security policy?
A) To punish employees who violate rules
B) To provide a framework for protecting information assets
,C) To increase system performance
D) To reduce hardware costs
Answer: B
Rationale: Security policies establish the rules, procedures, and guidelines that
protect an organization's information assets and guide employee behavior.
---
3. Which regulation mandates that financial institutions protect customer data?
A) HIPAA
B) GLBA
C) SOX
D) FERPA
Answer: B
Rationale: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to
explain their information-sharing practices and protect sensitive customer data.
---
4. What does the term "risk appetite" refer to?
A) The amount of risk an organization is willing to accept
B) The total number of risks identified
,C) The cost of risk mitigation
D) The frequency of security audits
Answer: A
Rationale: Risk appetite is the level of risk that an organization is prepared to
accept in pursuit of its objectives, guiding risk management decisions.
---
5. Which of the following is a corrective control?
A) Firewall
B) Antivirus software
C) Data backup and recovery
D) Security awareness training
Answer: C
Rationale: Corrective controls restore systems after an incident. Backups allow
recovery, while firewalls and antivirus are preventive, and training is deterrent.
---
6. What is the primary purpose of a Security Information and Event Management
(SIEM) system?
A) To encrypt data at rest
, B) To aggregate and analyze security logs
C) To manage user passwords
D) To scan for malware
Answer: B
Rationale: SIEM solutions collect and correlate log data from across the network
to detect anomalies and security incidents in real-time.
---
7. Which risk treatment strategy involves doing nothing to address a risk?
A) Risk Acceptance
B) Risk Avoidance
C) Risk Transference
D) Risk Mitigation
Answer: A
Rationale: Risk acceptance means acknowledging the risk and choosing to take no
action, usually because the cost of mitigation exceeds the potential loss.
---
8. What is the difference between a threat and a vulnerability?
A) A threat is a weakness; a vulnerability is an attacker