Be able to read a scenario, identify the applicable CIS Control or Implementation Group, and justify the choice by the safeguard's intent. The single most important thing: know that CIS Controls are prioritized by Implementation Group, with basic hygiene controls first.
Start practicing
Security Frameworks and CIS Controls — choose a session length
Free · No account required
Domain overview
This domain covers the CIS Critical Security Controls and the broader frameworks GSEC candidates must map to real operations: control numbering and Implementation Groups, CIS Benchmarks, NIST CSF functions, ISO/IEC 27001, and how controls translate into measurable, auditable security program activities. Questions present business scenarios and ask which control, group, or artifact applies.
Exam objectives
CIS Control 1 inventory of hardware and Control 2 inventory of software as foundational visibility controls
CIS Implementation Group 1, 2, and 3 scoping based on risk profile and limited resources
CIS Control 4 secure configuration via hardened baselines such as CIS Benchmarks for OS images
CIS Control 6 access control management covering account provisioning, review, and deprovisioning lifecycle
Confusing CIS Implementation Groups with NIST CSF tiers or maturity levels; IG1 is the basic safeguard subset for limited-resource entities.
Assuming CIS Controls are ordered strictly by number as implementation priority rather than grouped by IG and function.
Treating framework mapping as one-to-one; a single CIS Control can satisfy multiple NIST CSF or ISO/IEC 27001 requirements.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your organization is adopting the CIS Critical Security Controls to bolster defense. You are currently focused on establishing a secure baseline configuration for all workstation images. Which specific CIS Control should you prioritize to ensure that unauthorized software and unauthorized configuration changes are mitigated?
2An organization is performing a gap analysis against the CIS Controls. They find that while they have strong identity management, they fail to track the software installed on local machines, leading to 'shadow IT.' Which CIS Control should they implement to address this specific visibility gap?
3An organization is reviewing CIS Control 11: Data Recovery. Which of the following activities best demonstrates adherence to the 'testing' requirement of this control?
4An organization is applying CIS Control 9: Email and Web Browser Protections. They have successfully implemented domain-based message authentication (DMARC). What is the primary security goal being achieved by this implementation?
5A financial services firm is aligning its security program with the CIS Critical Security Controls. The CISO wants to ensure that the organization can measure the effectiveness of its security posture over time and prioritize improvements. Which of the following should the security team implement to achieve this?
6A healthcare organization is implementing CIS Control 14: Security Awareness and Skills Training. The security manager needs to ensure that the training program effectively reduces phishing susceptibility among employees. Which of the following approaches best aligns with the control's requirements?
7A financial services company is aligning its security program with the CIS Critical Security Controls. The CISO asks you to identify which Implementation Group (IG) is most appropriate for a small startup with limited IT staff that handles only publicly available data and has no regulatory compliance obligations. Which IG should you recommend?
8A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?
9A retail company is adopting the CIS Critical Security Controls and wants to prioritize its efforts. According to the CIS Controls, which of the following is the first basic control that should be implemented to gain visibility into assets?
10A financial services firm has implemented all 18 CIS Critical Security Controls at Implementation Group 2. During a board presentation, the CISO is asked how the organization should measure the effectiveness of its security program. Which of the following best describes the role of Implementation Groups within the CIS Controls framework?
11A university is implementing CIS Control 6: Access Control Management. They want to ensure that user accounts are properly managed. Which of the following actions best aligns with the requirement to manage the lifecycle of user accounts?
12A healthcare provider is aligning its security program with the CIS Critical Security Controls. The security team is tasked with implementing CIS Control 1: Inventory and Control of Enterprise Assets. Which of the following activities is the most critical first step to ensure the control is effectively implemented?
13A small marketing agency has limited IT staff and resources. They are looking to adopt a security framework to protect their assets. They have heard about the CIS Critical Security Controls and want to know which Implementation Group is most appropriate for their situation. Which of the following should they choose?
14A multinational corporation is aligning its incident response program with the CIS Critical Security Controls. They are focusing on CIS Control 17: Incident Response Management. Which of the following activities best demonstrates the establishment of a formal incident response process as required by this control?
15A mid-sized healthcare provider has adopted the CIS Critical Security Controls and wants to measure the effectiveness of its security program over time. The CISO asks you to recommend a method that provides a quantifiable, repeatable score of how well the organization is implementing the CIS Controls. Which approach best meets this requirement?
Be able to read a scenario, identify the applicable CIS Control or Implementation Group, and justify the choice by the safeguard's intent. The single most important thing: know that CIS Controls are prioritized by Implementation Group, with basic hygiene controls first.
The Courseiva GSEC question bank contains 15 questions in the Security Frameworks and CIS Controls domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Frameworks and CIS Controls domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included