GSEC Security Frameworks and CIS Controls Practice Question
A financial services company is aligning its security program with the CIS Critical Security Controls. The CISO asks you to identify which Implementation Group (IG) is most appropriate for a small startup with limited IT staff that handles only publicly available data and has no regulatory compliance obligations. Which IG should you recommend?
⚠ Common exam trap
The trap here is assuming that a higher Implementation Group always provides better security, when in fact the appropriate IG depends on risk profile and available resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IG1
IG1 is the correct choice because it provides a foundational set of safeguards tailored to small organizations with limited resources and low-risk data. It focuses on essential cyber hygiene that addresses the most common attack vectors. For a startup with no sensitive data or regulatory requirements, IG1 offers a realistic and effective starting point without overburdening its IT staff.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IG1
Why this is correct
IG1 is designed for small organizations with limited resources and low data sensitivity. It consists of essential cyber hygiene safeguards that provide a baseline defense against general, non-targeted attacks. Since the startup handles only public data and has no compliance mandates, IG1 is the proportionate starting point.
- ✗
IG0
Why it's wrong here
IG0 is not a recognized Implementation Group in the CIS Critical Security Controls framework. The CIS Controls define only IG1, IG2, and IG3. Choosing IG0 would indicate a misunderstanding of the framework's structure and would not provide a valid roadmap for the startup's security program.
- ✗
IG2
Why it's wrong here
IG2 is intended for organizations that manage sensitive client or enterprise data and face moderate risk. It includes all IG1 safeguards plus additional controls for access management, logging, and vulnerability management. Applying IG2 here would impose unnecessary overhead on a small startup with no sensitive data or compliance drivers.
- ✗
IG3
Why it's wrong here
IG3 targets large, mature organizations with dedicated security teams and high-value assets, such as those in critical infrastructure or regulated industries. It requires advanced controls like application whitelisting and network segmentation. This startup lacks the resources and risk profile that justify IG3 implementation.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.