IT INFRASTRUCTURE AND
GOVERNANCE FRAMEWORKS EXAM
2025/2026 QUESTIONS AND ANSWERS
100% PASS
Cybersecurity framework (CSF) - ANS Developing a set of plain language controls for the
protection of critical IT infrastructure. The focus of the framework core is to develop a program
to identify, assess, and manage cybersecurity risks in a cost-effective and repeatable manner.
Framework Core - ANS Involves identifying assets, system users, information processes,
operations, and all systems used; protecting by deploying safeguards, access controls,
performing regular updates and data backups, and having plans for disposing of files or unused
data; detecting active cybersecurity attacks, monitoring network access points, user devices,
unauthorized personnel access, and high-risk employee behavior or the use of high-risk devices;
responding with policies to contain cybersecurity events, react using planned responses that
mitigate losses, and notify all parties affected; and recovering by supporting the restoration of a
company's network to normal operations, restoring backup files or environments, and
positioning employees to rebound with the proper response.
Framework Tiers - ANS Measure an organization's information security sophistication and act
as a benchmark, not a means of implementing. Includes Tier 1 (Partial), Tier 2 (Risk Informed),
Tier 3 (Repeatable), and Tier 4 (Adoptive).
Privacy Framework - ANS Involves identifying privacy risks related to data processing
activities, establishing governance and management structures, driving dialogue around privacy
risks, implementing safeguards, detecting data privacy risks and events, responding to data
privacy events, and recovering business operations after data privacy events.
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, Security and Privacy Controls (SP 800-53) - ANS A strict standard with nearly 1,200 detailed
controls designed to protect against sophisticated threats. Applicable to all federal information
systems, providing a stricter standard than NIST CSF or Privacy Frameworks. Implementation
can be costly and burdensome.
HIPAA - ANS Governs the privacy of protected health information (PHI) and applies to
covered entities like healthcare providers, health plans, health care clearinghouses, and service
providers. It mandates safeguards for electronic PHI, including confidentiality, integrity,
availability, protection against threats, impermissible uses or disclosures, and compliance by
the covered entity's workforce.
GDPR - ANS General Data Protection Regulation is one of the strictest privacy laws globally,
providing circumstances for lawful data processing, applying to data processors based in the
EU, even if processing occurs outside the EU, and to those not based in the EU but offering
goods/services to or monitoring individuals in the EU. It is based on six principles including
lawfulness, fairness, transparency, and purpose limitation.
Data Minimization - ANS Process only necessary data for the purpose
Accuracy - ANS Ensure data is precise and regularly updated
Storage Limitation - ANS Store data only for necessary periods
Integrity and Confidentiality - ANS Secure data against unauthorized access or loss
PCI DSS - ANS Payment Card Industry Security Standard
Network Security Controls - ANS Maintain secure network and system configurations
Secure Configurations - ANS Apply safe settings to system components
Vulnerability Management Program - ANS Protect systems from malicious software
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
GOVERNANCE FRAMEWORKS EXAM
2025/2026 QUESTIONS AND ANSWERS
100% PASS
Cybersecurity framework (CSF) - ANS Developing a set of plain language controls for the
protection of critical IT infrastructure. The focus of the framework core is to develop a program
to identify, assess, and manage cybersecurity risks in a cost-effective and repeatable manner.
Framework Core - ANS Involves identifying assets, system users, information processes,
operations, and all systems used; protecting by deploying safeguards, access controls,
performing regular updates and data backups, and having plans for disposing of files or unused
data; detecting active cybersecurity attacks, monitoring network access points, user devices,
unauthorized personnel access, and high-risk employee behavior or the use of high-risk devices;
responding with policies to contain cybersecurity events, react using planned responses that
mitigate losses, and notify all parties affected; and recovering by supporting the restoration of a
company's network to normal operations, restoring backup files or environments, and
positioning employees to rebound with the proper response.
Framework Tiers - ANS Measure an organization's information security sophistication and act
as a benchmark, not a means of implementing. Includes Tier 1 (Partial), Tier 2 (Risk Informed),
Tier 3 (Repeatable), and Tier 4 (Adoptive).
Privacy Framework - ANS Involves identifying privacy risks related to data processing
activities, establishing governance and management structures, driving dialogue around privacy
risks, implementing safeguards, detecting data privacy risks and events, responding to data
privacy events, and recovering business operations after data privacy events.
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, Security and Privacy Controls (SP 800-53) - ANS A strict standard with nearly 1,200 detailed
controls designed to protect against sophisticated threats. Applicable to all federal information
systems, providing a stricter standard than NIST CSF or Privacy Frameworks. Implementation
can be costly and burdensome.
HIPAA - ANS Governs the privacy of protected health information (PHI) and applies to
covered entities like healthcare providers, health plans, health care clearinghouses, and service
providers. It mandates safeguards for electronic PHI, including confidentiality, integrity,
availability, protection against threats, impermissible uses or disclosures, and compliance by
the covered entity's workforce.
GDPR - ANS General Data Protection Regulation is one of the strictest privacy laws globally,
providing circumstances for lawful data processing, applying to data processors based in the
EU, even if processing occurs outside the EU, and to those not based in the EU but offering
goods/services to or monitoring individuals in the EU. It is based on six principles including
lawfulness, fairness, transparency, and purpose limitation.
Data Minimization - ANS Process only necessary data for the purpose
Accuracy - ANS Ensure data is precise and regularly updated
Storage Limitation - ANS Store data only for necessary periods
Integrity and Confidentiality - ANS Secure data against unauthorized access or loss
PCI DSS - ANS Payment Card Industry Security Standard
Network Security Controls - ANS Maintain secure network and system configurations
Secure Configurations - ANS Apply safe settings to system components
Vulnerability Management Program - ANS Protect systems from malicious software
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED