GSEC Security Frameworks and CIS Controls Practice Question
A small marketing agency has limited IT staff and resources. They are looking to adopt a security framework to protect their assets. They have heard about the CIS Critical Security Controls and want to know which Implementation Group is most appropriate for their situation. Which of the following should they choose?
⚠ Common exam trap
The trap here is assuming that a higher Implementation Group always means better security, leading to the selection of IG2 or IG3 when IG1 is more appropriate for the organization's size and risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementation Group 1 (IG1) because it provides foundational cyber hygiene suitable for organizations with limited resources.
Implementation Group 1 (IG1) is specifically designed for small organizations with limited resources. It offers a foundational set of 56 safeguards that address the most common cyber threats. For a small marketing agency, IG1 provides a manageable and effective starting point to improve security posture without requiring extensive resources or expertise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementation Group 1 (IG1) because it provides foundational cyber hygiene suitable for organizations with limited resources.
Why this is correct
IG1 is designed for small organizations with limited resources and low risk. It includes 56 basic safeguards that represent essential cyber hygiene. For a small marketing agency, IG1 provides a practical starting point to protect against common threats without overwhelming their IT staff. It is the recommended baseline for all organizations, regardless of size, but is particularly suited for those with constrained resources.
- ✗
Implementation Group 3 (IG3) because it offers the highest level of security.
Why it's wrong here
IG3 is for high-risk organizations with significant resources, such as large enterprises or critical infrastructure. A small marketing agency does not typically face the same threat landscape and lacks the resources to implement all 153 safeguards. Choosing IG3 would be impractical and could lead to incomplete implementation and wasted effort.
- ✗
Implementation Group 2 (IG2) because it includes additional safeguards for moderate risk organizations.
Why it's wrong here
IG2 is intended for organizations with moderate risk and more resources. A small marketing agency with limited IT staff may find IG2's 130 safeguards overwhelming and unnecessary if their risk profile is low. While they could eventually progress to IG2, starting with IG1 is more appropriate to build a foundation without overextending resources.
- ✗
None of the Implementation Groups; they should develop a custom framework from scratch.
Why it's wrong here
Developing a custom framework is unnecessary and inefficient. The CIS Controls, particularly IG1, provide a well-vetted set of safeguards that address common threats. A small agency can adopt IG1 and tailor it as needed. Creating a custom framework would require significant expertise and time, which they likely lack.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.