Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 97 pages
Exam (elaborations)

CITP Exam Preparation 2026/2027 | Complete Practice Questions & Detailed Rationales | Certified Information Technology Professional

Document preview thumbnail
Preview 4 out of 97 pages

CITP Exam Preparation 2026/2027 | Complete Practice Questions & Detailed Rationales | Certified Information Technology Professional

Content preview

CITP Exam Preparation 2026/2027 | Complete Practice
Questions & Detailed Rationales | Certified Information
Technology Professional


Information Security Governance & Cyber Risk
1. Which objective is most important when establishing an
information security governance program?
A. Maximizing technology spending
B. Aligning security objectives with organizational objectives
C. Eliminating every possible cyber threat
D. Replacing all legacy systems
Answer: B
Rationale: Security governance should support organizational
objectives while managing information-security risks. No organization
can eliminate every possible threat.
2. What is the primary purpose of an information security policy?
A. Define management's security expectations and requirements
B. Describe individual employee salaries
C. Replace technical security controls
D. Eliminate the need for risk assessments
Answer: A
Rationale: Security policies establish management expectations,
responsibilities, acceptable behavior, and required security practices.
3. Which principle requires users to receive only the access necessary
to perform assigned duties?
A. Defense in depth

,B. Least privilege
C. Nonrepudiation
D. Availability
Answer: B
Rationale: Least privilege minimizes exposure by limiting permissions to
those required for legitimate business activities.
4. Which control is primarily preventive?
A. Reviewing an audit log after an incident
B. Firewall blocking unauthorized traffic
C. Investigating a completed breach
D. Reconciling an exception report
Answer: B
Rationale: Preventive controls are designed to stop undesirable events
before they occur.
5. What is the main purpose of multifactor authentication?
A. Increase storage capacity
B. Require multiple independent authentication factors
C. Encrypt every database
D. Improve network bandwidth
Answer: B
Rationale: MFA strengthens authentication by requiring two or more
distinct factors, such as something known, possessed, or inherent.
6. Which is an example of "something you know"?
A. Fingerprint
B. Smart card
C. Password
D. Hardware token

,Answer: C
Rationale: Passwords and PINs are knowledge-based authentication
factors.
7. Which security objective is primarily concerned with preventing
unauthorized disclosure?
A. Availability
B. Confidentiality
C. Processing integrity
D. Recoverability
Answer: B
Rationale: Confidentiality protects information from unauthorized
access or disclosure.
8. Which security objective ensures information is accurate and has
not been improperly altered?
A. Integrity
B. Availability
C. Confidentiality
D. Scalability
Answer: A
Rationale: Integrity protects information against unauthorized or
inappropriate modification.
9. Which security objective focuses on ensuring authorized users can
access systems when needed?
A. Confidentiality
B. Availability
C. Authentication
D. Encryption

, Answer: B
Rationale: Availability concerns reliable and timely access to systems
and information.
10. What is the best first step in managing a significant information-
security risk?
A. Purchase security software
B. Identify and assess the risk
C. Notify customers immediately
D. Delete the affected system
Answer: B
Rationale: Risk management begins by understanding the asset, threat,
vulnerability, likelihood, and potential impact.
11. Risk appetite refers to:
A. The amount and type of risk an organization is willing to accept
B. Every risk identified by internal audit
C. The total number of cyberattacks experienced
D. The organization's insurance premium
Answer: A
Rationale: Risk appetite represents the level and nature of risk
management is willing to accept in pursuit of objectives.
12. What does risk tolerance describe?
A. The organization's maximum acceptable variation around objectives
B. The number of security employees
C. The value of IT assets
D. The amount of cybersecurity insurance
Answer: A

Document information

Uploaded on
September 14, 2026
Number of pages
97
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(24)
Sold
113
Followers
3
Items
8668
Last sold
18 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions