GSEC Security Frameworks and CIS Controls Practice Question
A financial services firm is aligning its security program with the CIS Critical Security Controls. The CISO wants to ensure that the organization can measure the effectiveness of its security posture over time and prioritize improvements. Which of the following should the security team implement to achieve this?
⚠ Common exam trap
The trap here is assuming that any recognized framework or tool (like NIST CSF or a SIEM) can fulfill the need for a CIS Controls-specific measurement and prioritization method, when only CIS RAM is purpose-built for that.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adopt the CIS Risk Assessment Method (CIS RAM) to identify, analyze, and prioritize risks based on the CIS Controls.
CIS RAM is specifically designed to help organizations implement the CIS Controls by providing a repeatable, risk-based assessment method. It enables the security team to measure the effectiveness of controls, identify gaps, and prioritize remediation efforts. Other options, while valuable, do not offer the same direct alignment with CIS Controls for measuring and improving security posture over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adopt the CIS Risk Assessment Method (CIS RAM) to identify, analyze, and prioritize risks based on the CIS Controls.
Why this is correct
CIS RAM is a prescriptive risk assessment method designed to help organizations implement the CIS Controls by identifying and prioritizing risks. It provides a structured approach to measure security posture and make informed decisions about resource allocation, directly supporting the CISO's goal of tracking effectiveness and prioritizing improvements.
- ✗
Conduct a penetration test to identify vulnerabilities in the organization's external-facing infrastructure.
Why it's wrong here
Penetration testing is a point-in-time activity that identifies technical vulnerabilities but does not provide a continuous measurement of security posture across all CIS Controls. It fails to address the need for a structured, repeatable method to assess and prioritize improvements aligned with the CIS Controls framework.
- ✗
Deploy a SIEM solution to collect and correlate security events from all network devices.
Why it's wrong here
A SIEM enhances detection and response capabilities but does not measure the effectiveness of the overall security program against the CIS Controls. It focuses on monitoring and alerting rather than providing a risk-based assessment and prioritization mechanism, which is what the CISO requires to track posture and drive improvements.
- ✗
Implement the NIST Cybersecurity Framework to map current activities to the five core functions.
Why it's wrong here
While the NIST CSF provides a common language for cybersecurity activities, it is not specifically designed to measure the effectiveness of CIS Controls implementation. The scenario requires alignment with CIS Controls and a method to prioritize improvements; NIST CSF alone does not offer the granular, control-specific assessment and prioritization that CIS RAM provides.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.