CITP Exam Preparation 2026/2027 | Complete Practice
Questions & Detailed Rationales | Certified Information
Technology Professional
Information Security Governance & Cyber Risk
1. Which objective is most important when establishing an
information security governance program?
A. Maximizing technology spending
B. Aligning security objectives with organizational objectives
C. Eliminating every possible cyber threat
D. Replacing all legacy systems
Answer: B
Rationale: Security governance should support organizational
objectives while managing information-security risks. No organization
can eliminate every possible threat.
2. What is the primary purpose of an information security policy?
A. Define management's security expectations and requirements
B. Describe individual employee salaries
C. Replace technical security controls
D. Eliminate the need for risk assessments
Answer: A
Rationale: Security policies establish management expectations,
responsibilities, acceptable behavior, and required security practices.
3. Which principle requires users to receive only the access necessary
to perform assigned duties?
A. Defense in depth
,B. Least privilege
C. Nonrepudiation
D. Availability
Answer: B
Rationale: Least privilege minimizes exposure by limiting permissions to
those required for legitimate business activities.
4. Which control is primarily preventive?
A. Reviewing an audit log after an incident
B. Firewall blocking unauthorized traffic
C. Investigating a completed breach
D. Reconciling an exception report
Answer: B
Rationale: Preventive controls are designed to stop undesirable events
before they occur.
5. What is the main purpose of multifactor authentication?
A. Increase storage capacity
B. Require multiple independent authentication factors
C. Encrypt every database
D. Improve network bandwidth
Answer: B
Rationale: MFA strengthens authentication by requiring two or more
distinct factors, such as something known, possessed, or inherent.
6. Which is an example of "something you know"?
A. Fingerprint
B. Smart card
C. Password
D. Hardware token
,Answer: C
Rationale: Passwords and PINs are knowledge-based authentication
factors.
7. Which security objective is primarily concerned with preventing
unauthorized disclosure?
A. Availability
B. Confidentiality
C. Processing integrity
D. Recoverability
Answer: B
Rationale: Confidentiality protects information from unauthorized
access or disclosure.
8. Which security objective ensures information is accurate and has
not been improperly altered?
A. Integrity
B. Availability
C. Confidentiality
D. Scalability
Answer: A
Rationale: Integrity protects information against unauthorized or
inappropriate modification.
9. Which security objective focuses on ensuring authorized users can
access systems when needed?
A. Confidentiality
B. Availability
C. Authentication
D. Encryption
, Answer: B
Rationale: Availability concerns reliable and timely access to systems
and information.
10. What is the best first step in managing a significant information-
security risk?
A. Purchase security software
B. Identify and assess the risk
C. Notify customers immediately
D. Delete the affected system
Answer: B
Rationale: Risk management begins by understanding the asset, threat,
vulnerability, likelihood, and potential impact.
11. Risk appetite refers to:
A. The amount and type of risk an organization is willing to accept
B. Every risk identified by internal audit
C. The total number of cyberattacks experienced
D. The organization's insurance premium
Answer: A
Rationale: Risk appetite represents the level and nature of risk
management is willing to accept in pursuit of objectives.
12. What does risk tolerance describe?
A. The organization's maximum acceptable variation around objectives
B. The number of security employees
C. The value of IT assets
D. The amount of cybersecurity insurance
Answer: A
Questions & Detailed Rationales | Certified Information
Technology Professional
Information Security Governance & Cyber Risk
1. Which objective is most important when establishing an
information security governance program?
A. Maximizing technology spending
B. Aligning security objectives with organizational objectives
C. Eliminating every possible cyber threat
D. Replacing all legacy systems
Answer: B
Rationale: Security governance should support organizational
objectives while managing information-security risks. No organization
can eliminate every possible threat.
2. What is the primary purpose of an information security policy?
A. Define management's security expectations and requirements
B. Describe individual employee salaries
C. Replace technical security controls
D. Eliminate the need for risk assessments
Answer: A
Rationale: Security policies establish management expectations,
responsibilities, acceptable behavior, and required security practices.
3. Which principle requires users to receive only the access necessary
to perform assigned duties?
A. Defense in depth
,B. Least privilege
C. Nonrepudiation
D. Availability
Answer: B
Rationale: Least privilege minimizes exposure by limiting permissions to
those required for legitimate business activities.
4. Which control is primarily preventive?
A. Reviewing an audit log after an incident
B. Firewall blocking unauthorized traffic
C. Investigating a completed breach
D. Reconciling an exception report
Answer: B
Rationale: Preventive controls are designed to stop undesirable events
before they occur.
5. What is the main purpose of multifactor authentication?
A. Increase storage capacity
B. Require multiple independent authentication factors
C. Encrypt every database
D. Improve network bandwidth
Answer: B
Rationale: MFA strengthens authentication by requiring two or more
distinct factors, such as something known, possessed, or inherent.
6. Which is an example of "something you know"?
A. Fingerprint
B. Smart card
C. Password
D. Hardware token
,Answer: C
Rationale: Passwords and PINs are knowledge-based authentication
factors.
7. Which security objective is primarily concerned with preventing
unauthorized disclosure?
A. Availability
B. Confidentiality
C. Processing integrity
D. Recoverability
Answer: B
Rationale: Confidentiality protects information from unauthorized
access or disclosure.
8. Which security objective ensures information is accurate and has
not been improperly altered?
A. Integrity
B. Availability
C. Confidentiality
D. Scalability
Answer: A
Rationale: Integrity protects information against unauthorized or
inappropriate modification.
9. Which security objective focuses on ensuring authorized users can
access systems when needed?
A. Confidentiality
B. Availability
C. Authentication
D. Encryption
, Answer: B
Rationale: Availability concerns reliable and timely access to systems
and information.
10. What is the best first step in managing a significant information-
security risk?
A. Purchase security software
B. Identify and assess the risk
C. Notify customers immediately
D. Delete the affected system
Answer: B
Rationale: Risk management begins by understanding the asset, threat,
vulnerability, likelihood, and potential impact.
11. Risk appetite refers to:
A. The amount and type of risk an organization is willing to accept
B. Every risk identified by internal audit
C. The total number of cyberattacks experienced
D. The organization's insurance premium
Answer: A
Rationale: Risk appetite represents the level and nature of risk
management is willing to accept in pursuit of objectives.
12. What does risk tolerance describe?
A. The organization's maximum acceptable variation around objectives
B. The number of security employees
C. The value of IT assets
D. The amount of cybersecurity insurance
Answer: A