Courseiva

CCNA Security Frameworks And Cis Controls Questions

15 questions · Security Frameworks And Cis Controls topic · All types, answers revealed

1
MCQmedium

A financial services firm has implemented all 18 CIS Critical Security Controls at Implementation Group 2. During a board presentation, the CISO is asked how the organization should measure the effectiveness of its security program. Which of the following best describes the role of Implementation Groups within the CIS Controls framework?

A.Implementation Groups are prioritized sets of safeguards tailored to an organization's risk profile and resources, with IG1 being foundational, IG2 for organizations with moderate risk, and IG3 for high-risk environments.
B.Implementation Groups are used exclusively by small businesses, while large enterprises must implement all 18 controls regardless of risk.
C.Implementation Groups are optional certifications that an organization can obtain to demonstrate compliance with the CIS Controls.
D.Implementation Groups are maturity levels that an organization must sequentially achieve, with IG1 being the lowest and IG3 the highest.
AnswerA

Implementation Groups categorize safeguards by risk and resource availability. IG1 provides foundational cyber hygiene for all organizations. IG2 adds safeguards for those with moderate risk and more resources. IG3 includes advanced safeguards for high-risk environments. This helps organizations prioritize and measure progress against a relevant subset of controls, making it a practical effectiveness measurement tool.

Why this answer

Implementation Groups provide a risk-based approach to adopting the CIS Controls. They help organizations prioritize safeguards according to their specific risk profile and resources, rather than a one-size-fits-all model. IG1 is foundational for all, IG2 adds for moderate risk, and IG3 for high-risk.

This allows the firm to measure effectiveness by assessing implementation of the relevant safeguards within its chosen IG.

Exam trap

The trap here is assuming that Implementation Groups are maturity levels that must be achieved sequentially, rather than risk-based categories for prioritization.

2
MCQmedium

An organization is performing a gap analysis against the CIS Controls. They find that while they have strong identity management, they fail to track the software installed on local machines, leading to 'shadow IT.' Which CIS Control should they implement to address this specific visibility gap?

A.CIS Control 1: Inventory and Control of Enterprise Assets
B.CIS Control 2: Inventory and Control of Software Assets
C.CIS Control 3: Data Protection
D.CIS Control 7: Continuous Vulnerability Management
AnswerB

Control 2 requires maintaining an up-to-date inventory of all software installed on enterprise assets. This ensures that unauthorized software (shadow IT) can be detected and managed. By enforcing this control, security teams gain the visibility needed to authorize or remove applications, closing the gap described in the scenario.

Why this answer

The organization's issue involves a lack of visibility into what software is running on their endpoints, which is a classic symptom of failing CIS Control 2: Inventory and Control of Software Assets. By implementing this control, organizations can maintain an authoritative list of authorized software and detect unauthorized installations, ensuring that only approved, vetted applications exist on the network, thereby reducing the risk of malware and compliance violations.

Exam trap

Candidates frequently select 'Control 1: Inventory of Enterprise Assets' instead of Control 2. They miss that the prompt specifically highlights 'software installed' rather than the hardware inventory itself.

3
MCQmedium

Your organization is adopting the CIS Critical Security Controls to bolster defense. You are currently focused on establishing a secure baseline configuration for all workstation images. Which specific CIS Control should you prioritize to ensure that unauthorized software and unauthorized configuration changes are mitigated?

A.CIS Control 1: Inventory and Control of Enterprise Assets
B.CIS Control 2: Data Protection
C.CIS Control 4: Secure Configuration of Enterprise Assets and Software
D.CIS Control 8: Audit Log Management
AnswerC

Control 4 specifically requires the establishment and maintenance of secure configurations for all enterprise assets. It ensures that systems are deployed with hardened settings, unnecessary ports are closed, and only authorized software is permitted. This effectively mitigates the risk of exploitation through default settings or unauthorized application execution.

Why this answer

CIS Control 4, Secure Configuration of Enterprise Assets and Software, focuses on establishing and maintaining security configurations for hardware and software. By mandating a standardized, hardened baseline for all workstations, the organization reduces the attack surface by eliminating unnecessary services and insecure settings. This is a foundational control that directly supports other security measures by ensuring that endpoints are in a known, secure state before they are deployed into the production network environment.

Exam trap

Candidates frequently confuse Control 4 (Secure Configuration) with Control 5 (Account Management) or Control 7 (Vulnerability Management), missing that the prompt specifically asks about workstation images and unauthorized configuration changes.

4
MCQmedium

An organization is applying CIS Control 9: Email and Web Browser Protections. They have successfully implemented domain-based message authentication (DMARC). What is the primary security goal being achieved by this implementation?

A.Encryption of email traffic between mail servers.
B.Prevention of unauthorized use of the organization's domain for spoofing.
C.Hardening web browser settings to prevent XSS attacks.
D.Scanning of inbound email attachments for malware signatures.
AnswerB

DMARC specifically enables domain owners to protect their domain from being used for email spoofing. It provides a feedback mechanism and policy enforcement that tells receiving mail servers how to reject or quarantine emails that do not pass SPF or DKIM authentication, directly preventing domain impersonation and phishing.

Why this answer

DMARC is a critical component of CIS Control 9 because it builds upon SPF and DKIM to prevent email spoofing and phishing attacks. By allowing domain owners to publish instructions on how receiving servers should handle emails that fail authentication, it significantly reduces the efficacy of fraudulent emails, thereby protecting the organization's reputation and preventing users from interacting with malicious content that leverages the organization's legitimate email domain.

Exam trap

Candidates often confuse DMARC with encryption protocols like TLS or general spam filtering, missing its specific focus on domain spoofing prevention.

5
MCQmedium

A financial services company is aligning its security program with the CIS Critical Security Controls. The CISO asks you to identify which Implementation Group (IG) is most appropriate for a small startup with limited IT staff that handles only publicly available data and has no regulatory compliance obligations. Which IG should you recommend?

A.IG1
B.IG0
C.IG2
D.IG3
AnswerA

IG1 is designed for small organizations with limited resources and low data sensitivity. It consists of essential cyber hygiene safeguards that provide a baseline defense against general, non-targeted attacks. Since the startup handles only public data and has no compliance mandates, IG1 is the proportionate starting point.

Why this answer

IG1 is the correct choice because it provides a foundational set of safeguards tailored to small organizations with limited resources and low-risk data. It focuses on essential cyber hygiene that addresses the most common attack vectors. For a startup with no sensitive data or regulatory requirements, IG1 offers a realistic and effective starting point without overburdening its IT staff.

Exam trap

The trap here is assuming that a higher Implementation Group always provides better security, when in fact the appropriate IG depends on risk profile and available resources.

6
MCQhard

A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?

A.Enabling full-disk encryption on all endpoints and servers that store protected health information.
B.Deploying a data loss prevention (DLP) solution to monitor outbound email containing patient data.
C.Configuring database backup files to be stored in a separate physical location with access controls.
D.Implementing TLS 1.2 for all web traffic to and from the electronic health record system.
AnswerA

CIS Control 3 explicitly requires encryption of data at rest on end-user devices and servers. Full-disk encryption protects data if a device is lost or stolen. This directly addresses the safeguard for data at rest, making it the correct action.

Why this answer

Full-disk encryption directly satisfies the CIS Control 3 requirement to encrypt data at rest on endpoints and servers. It ensures that if a device is lost or stolen, the stored data remains unreadable. Other options address data in transit, monitoring, or physical security, which are important but do not meet the specific encryption-at-rest mandate.

Exam trap

The trap here is confusing data-in-transit encryption with data-at-rest encryption, and assuming that any security measure involving data satisfies the control.

7
MCQhard

A healthcare provider is aligning its security program with the CIS Critical Security Controls. The security team is tasked with implementing CIS Control 1: Inventory and Control of Enterprise Assets. Which of the following activities is the most critical first step to ensure the control is effectively implemented?

A.Creating a formal policy that defines what constitutes an enterprise asset and assigns ownership for maintaining the inventory.
B.Deploying an automated asset discovery tool to scan the network for all connected devices.
C.Implementing a configuration management database (CMDB) to store asset information.
D.Conducting a manual inventory of all assets in the data center.
AnswerA

CIS Control 1 begins with establishing and maintaining an inventory of enterprise assets. The foundational step is to define the scope and create a policy that specifies what assets are in scope, who owns them, and how the inventory will be maintained. This ensures that subsequent technical steps, like discovery and tracking, are aligned with business requirements and have clear accountability.

Why this answer

CIS Control 1 emphasizes the importance of a formalized process for inventory and control of enterprise assets. The initial step is to create a policy that defines the scope and assigns ownership. This ensures that the inventory is accurate, maintained, and aligned with organizational needs.

Without this governance, technical implementations may lack direction and accountability, leading to an ineffective control.

Exam trap

The trap here is focusing on the technical tool (such as an automated discovery tool or CMDB) as the first step, while overlooking the need for policy and ownership definition.

8
MCQhard

A multinational corporation is aligning its incident response program with the CIS Critical Security Controls. They are focusing on CIS Control 17: Incident Response Management. Which of the following activities best demonstrates the establishment of a formal incident response process as required by this control?

A.Establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures.
B.Designating a single individual as the incident response coordinator without a formal team.
C.Conducting an annual tabletop exercise without updating the incident response plan based on findings.
D.Purchasing an incident response automation tool to streamline handling of security incidents.
AnswerA

Safeguard 17.1 explicitly requires establishing and maintaining a documented incident response plan. This plan must define roles, responsibilities, and communication procedures. It is the cornerstone of CIS Control 17. A documented plan ensures that all stakeholders know their duties during an incident, facilitating a coordinated and effective response. This is the best demonstration of a formal process.

Why this answer

CIS Control 17 requires establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures. This formal documentation is the foundation of the incident response process. While tools, exercises, and designated personnel are valuable, they are not sufficient without a documented plan that guides the overall response effort.

Exam trap

The trap here is focusing on tools or exercises as the primary requirement, while overlooking the need for a documented incident response plan that defines roles and communication.

9
MCQmedium

A financial services firm is aligning its security program with the CIS Critical Security Controls. The CISO wants to ensure that the organization can measure the effectiveness of its security posture over time and prioritize improvements. Which of the following should the security team implement to achieve this?

A.Adopt the CIS Risk Assessment Method (CIS RAM) to identify, analyze, and prioritize risks based on the CIS Controls.
B.Conduct a penetration test to identify vulnerabilities in the organization's external-facing infrastructure.
C.Deploy a SIEM solution to collect and correlate security events from all network devices.
D.Implement the NIST Cybersecurity Framework to map current activities to the five core functions.
AnswerA

CIS RAM is a prescriptive risk assessment method designed to help organizations implement the CIS Controls by identifying and prioritizing risks. It provides a structured approach to measure security posture and make informed decisions about resource allocation, directly supporting the CISO's goal of tracking effectiveness and prioritizing improvements.

Why this answer

CIS RAM is specifically designed to help organizations implement the CIS Controls by providing a repeatable, risk-based assessment method. It enables the security team to measure the effectiveness of controls, identify gaps, and prioritize remediation efforts. Other options, while valuable, do not offer the same direct alignment with CIS Controls for measuring and improving security posture over time.

Exam trap

The trap here is assuming that any recognized framework or tool (like NIST CSF or a SIEM) can fulfill the need for a CIS Controls-specific measurement and prioritization method, when only CIS RAM is purpose-built for that.

10
MCQhard

An organization is reviewing CIS Control 11: Data Recovery. Which of the following activities best demonstrates adherence to the 'testing' requirement of this control?

A.Running a full system backup every night at 2:00 AM.
B.Storing all backup tapes in an off-site, climate-controlled facility.
C.Conducting a periodic, documented restore process to verify data integrity.
D.Encrypting all backup media to prevent unauthorized access.
AnswerC

Performing a documented, periodic restore test is the core requirement for Control 11. It proves that the backup system is working as intended, data is not corrupted, and the team knows the necessary steps to recover critical business systems within the required recovery time objectives after an incident.

Why this answer

The testing requirement in CIS Control 11 is critical because backups are useless if they cannot be successfully restored. Organizations must not only perform regular backups but also systematically test those backups to verify data integrity and recovery speed. This ensures that in the event of a ransomware attack or accidental data loss, the organization has a reliable, validated path to restore operations quickly and minimize downtime effectively.

Exam trap

Candidates often equate 'testing' with simply verifying that a backup job completed successfully. They miss that the actual requirement is to perform a restoration to verify data integrity.

11
MCQhard

A healthcare organization is implementing CIS Control 14: Security Awareness and Skills Training. The security manager needs to ensure that the training program effectively reduces phishing susceptibility among employees. Which of the following approaches best aligns with the control's requirements?

A.Implement a phishing simulation program with regular campaigns, provide immediate feedback to users who click, and track improvement over time.
B.Require employees to complete a computer-based training module on phishing once per quarter and pass a quiz.
C.Send monthly security newsletters to all staff highlighting recent phishing trends and best practices.
D.Conduct annual security awareness training for all employees and track completion rates.
AnswerA

This approach aligns with CIS Control 14 by providing continuous, practical training through simulated phishing attacks. Immediate feedback educates users in the moment, and tracking improvement measures the program's effectiveness. It goes beyond mere completion tracking to actively reduce susceptibility by reinforcing secure behavior and adapting training based on results.

Why this answer

CIS Control 14 emphasizes continuous security awareness training that includes simulated phishing exercises to test and reinforce employee skills. A program with regular phishing simulations, immediate feedback, and tracking of improvement directly measures and reduces susceptibility. Other options are either too infrequent or passive, failing to provide the practical, ongoing reinforcement that the control requires.

Exam trap

The trap here is equating security awareness with periodic training or communications, when CIS Control 14 specifically calls for simulated phishing and continuous reinforcement to effectively change behavior.

12
MCQeasy

A small marketing agency has limited IT staff and resources. They are looking to adopt a security framework to protect their assets. They have heard about the CIS Critical Security Controls and want to know which Implementation Group is most appropriate for their situation. Which of the following should they choose?

A.Implementation Group 1 (IG1) because it provides foundational cyber hygiene suitable for organizations with limited resources.
B.Implementation Group 3 (IG3) because it offers the highest level of security.
C.Implementation Group 2 (IG2) because it includes additional safeguards for moderate risk organizations.
D.None of the Implementation Groups; they should develop a custom framework from scratch.
AnswerA

IG1 is designed for small organizations with limited resources and low risk. It includes 56 basic safeguards that represent essential cyber hygiene. For a small marketing agency, IG1 provides a practical starting point to protect against common threats without overwhelming their IT staff. It is the recommended baseline for all organizations, regardless of size, but is particularly suited for those with constrained resources.

Why this answer

Implementation Group 1 (IG1) is specifically designed for small organizations with limited resources. It offers a foundational set of 56 safeguards that address the most common cyber threats. For a small marketing agency, IG1 provides a manageable and effective starting point to improve security posture without requiring extensive resources or expertise.

Exam trap

The trap here is assuming that a higher Implementation Group always means better security, leading to the selection of IG2 or IG3 when IG1 is more appropriate for the organization's size and risk.

13
MCQmedium

A mid-sized healthcare provider has adopted the CIS Critical Security Controls and wants to measure the effectiveness of its security program over time. The CISO asks you to recommend a method that provides a quantifiable, repeatable score of how well the organization is implementing the CIS Controls. Which approach best meets this requirement?

A.Deploy a vulnerability scanner across all subnets and track the total count of open vulnerabilities as the main indicator.
B.Conduct a penetration test against the external perimeter and use the number of critical findings as the primary metric.
C.Perform a CIS Controls Self Assessment Tool (CIS CSAT) using the CIS Controls Implementation Group criteria to generate a maturity score.
D.Calculate the mean time to remediate (MTTR) security incidents and present that as the sole measure of control effectiveness.
AnswerC

CIS CSAT is the official self-assessment tool that maps an organization's implementation of the CIS Controls to Implementation Groups and produces a quantifiable maturity score. It allows repeatable measurements over time, directly addressing the CISO's need to track program effectiveness and demonstrate progress against the CIS Controls framework.

Why this answer

The CIS Controls Self Assessment Tool (CSAT) is designed specifically to measure an organization's implementation of the CIS Controls and produce a quantifiable maturity score. It aligns with Implementation Groups and enables repeatable tracking over time. Other options focus on narrow technical metrics that do not assess the breadth of the CIS Controls or provide a consistent program-level score.

Exam trap

The trap here is confusing technical metrics like vulnerability counts or MTTR with a structured, control-based maturity assessment.

14
MCQeasy

A retail company is adopting the CIS Critical Security Controls and wants to prioritize its efforts. According to the CIS Controls, which of the following is the first basic control that should be implemented to gain visibility into assets?

A.Email and Web Browser Protections
B.Inventory and Control of Enterprise Assets
C.Continuous Vulnerability Management
D.Controlled Use of Administrative Privileges
AnswerB

CIS Control 1 is Inventory and Control of Enterprise Assets. It is the foundational control that requires maintaining an accurate, detailed inventory of all hardware and software. Without knowing what assets exist, other controls cannot be effectively applied. This is the first step in the CIS Controls.

Why this answer

Inventory and Control of Enterprise Assets is the first CIS Control because it establishes the foundation for all other controls. You cannot protect what you do not know exists. An accurate asset inventory enables effective vulnerability management, privilege control, and incident response.

The CIS Controls are prioritized, with Control 1 as the starting point for any organization.

Exam trap

The trap here is selecting a more technically appealing control like vulnerability management, overlooking that asset inventory is the prerequisite for all other controls.

15
MCQmedium

A university is implementing CIS Control 6: Access Control Management. They want to ensure that user accounts are properly managed. Which of the following actions best aligns with the requirement to manage the lifecycle of user accounts?

A.Conducting quarterly reviews of all user accounts to identify and disable inactive accounts.
B.Implementing multi-factor authentication for all administrative access to servers.
C.Deploying a privileged access management (PAM) solution to vault administrative credentials.
D.Enforcing a password complexity policy that requires 12 characters with mixed case and symbols.
AnswerA

CIS Control 6 requires managing the lifecycle of user accounts, including periodic reviews to disable inactive accounts. Quarterly reviews help ensure that accounts are removed when no longer needed, reducing the attack surface. This action directly supports the control's intent.

Why this answer

Quarterly reviews of user accounts directly support the lifecycle management requirement of CIS Control 6. By identifying and disabling inactive accounts, the university reduces the risk of unauthorized access through stale credentials. Other actions like password policies, MFA, and PAM are valuable but do not fulfill the specific need to manage account lifecycles across all users.

Exam trap

The trap here is focusing on authentication mechanisms like MFA or password policies, which are important but not the same as account lifecycle management.

Ready to test yourself?

Try a timed practice session using only Security Frameworks And Cis Controls questions.

CCNA Security Frameworks And Cis Controls Questions | Courseiva