MANAGEMENT | 2026/2027 TASK 1
PRACTICE EXAM | 100 QUESTIONS,
ANSWERS & DETAILED RATIONALES | A+
GRADED | PASS GUARANTEED!!
1.
A cybersecurity manager is developing a security program. What should be the
PRIMARY objective of the program?
A. Eliminate every possible cyber threat
B. Align security activities with organizational objectives and risk
C. Purchase the most expensive security technologies
D. Prevent employees from accessing the internet
Answer: B. Align security activities with organizational objectives and risk
Rationale: Cybersecurity management is fundamentally about managing organizational risk
while supporting business objectives. No security program can eliminate every possible
threat.
2.
Which three principles form the CIA triad?
A. Control, Investigation, Authorization
B. Confidentiality, Integrity, Availability
C. Compliance, Identification, Authentication
D. Continuity, Inspection, Accountability
Answer: B. Confidentiality, Integrity, Availability
Rationale: The CIA triad provides a fundamental framework for protecting information:
confidentiality prevents unauthorized disclosure, integrity protects accuracy and
completeness, and availability ensures authorized access when needed.
3.
,Which security principle ensures that information is accessible only to authorized
individuals?
A. Availability
B. Integrity
C. Confidentiality
D. Accountability
Answer: C. Confidentiality
Rationale: Confidentiality protects information from unauthorized disclosure or access.
4.
A company implements controls to prevent unauthorized modification of financial
records. Which CIA principle is MOST directly addressed?
A. Confidentiality
B. Integrity
C. Availability
D. Nonrepudiation
Answer: B. Integrity
Rationale: Integrity ensures that information remains accurate, complete, and protected
against unauthorized alteration.
5.
A business deploys redundant servers so customers can continue using its website if one
server fails. Which security principle is being supported?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: C. Availability
Rationale: Availability ensures systems and information remain accessible to authorized
users when required.
6.
,What is risk appetite?
A. The amount and type of risk an organization is willing to accept
B. The number of vulnerabilities discovered during scanning
C. The total cost of cybersecurity controls
D. The probability that an attack will occur
Answer: A. The amount and type of risk an organization is willing to accept
Rationale: Risk appetite represents the organization's overall willingness to accept risk while
pursuing its objectives.
7.
What is risk tolerance?
A. The organization's exact cybersecurity budget
B. The acceptable level of variation around risk objectives
C. The number of employees in the security department
D. The organization's total number of threats
Answer: B. The acceptable level of variation around risk objectives
Rationale: Risk tolerance establishes boundaries for acceptable deviations from
organizational objectives and risk expectations.
8.
Which equation is commonly used to conceptualize cybersecurity risk?
A. Risk = Asset + Control
B. Risk = Threat × Vulnerability × Impact
C. Risk = Budget − Vulnerability
D. Risk = Control × Availability
Answer: B. Risk = Threat × Vulnerability × Impact
Rationale: Risk analysis commonly considers the threat, the vulnerability being exploited,
and the resulting business impact.
9.
, Which risk response involves implementing controls to reduce the probability or impact
of a risk?
A. Accept
B. Transfer
C. Mitigate
D. Avoid
Answer: C. Mitigate
Rationale: Risk mitigation reduces risk through safeguards, processes, policies, or other
controls.
10.
Purchasing cybersecurity insurance is an example of which risk response?
A. Avoidance
B. Transfer
C. Acceptance
D. Elimination
Answer: B. Transfer
Rationale: Risk transfer shifts some financial consequences of a risk to another party, such as
an insurer.
11.
A company decides not to offer an internet-facing service because the associated
security risk cannot be justified. Which response is being used?
A. Mitigation
B. Transfer
C. Acceptance
D. Avoidance
Answer: D. Avoidance
Rationale: Risk avoidance involves eliminating the activity or condition that creates the
unacceptable risk.
12.