Courseiva

GSEC · topic practice

Security Frameworks and CIS Controls practice questions

This domain covers the CIS Critical Security Controls and the broader frameworks GSEC candidates must map to real operations: control numbering and Implementation Groups, CIS Benchmarks, NIST CSF functions, ISO/IEC 27001, and how controls translate into measurable, auditable security program activities. Questions present business scenarios and ask which control, group, or artifact applies.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Frameworks and CIS Controls

What the exam tests

What to know about Security Frameworks and CIS Controls

Be able to read a scenario, identify the applicable CIS Control or Implementation Group, and justify the choice by the safeguard's intent. The single most important thing: know that CIS Controls are prioritized by Implementation Group, with basic hygiene controls first.

CIS Control 1 inventory of hardware and Control 2 inventory of software as foundational visibility controls

CIS Implementation Group 1, 2, and 3 scoping based on risk profile and limited resources

CIS Control 4 secure configuration via hardened baselines such as CIS Benchmarks for OS images

CIS Control 6 access control management covering account provisioning, review, and deprovisioning lifecycle

Why learners struggle

Why Security Frameworks and CIS Controls questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Security Frameworks and CIS Controls exam traps

  • ▸Confusing CIS Implementation Groups with NIST CSF tiers or maturity levels; IG1 is the basic safeguard subset for limited-resource entities.
  • ▸Assuming CIS Controls are ordered strictly by number as implementation priority rather than grouped by IG and function.
  • ▸Treating framework mapping as one-to-one; a single CIS Control can satisfy multiple NIST CSF or ISO/IEC 27001 requirements.

Practice set

Security Frameworks and CIS Controls questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit. An automated audit script returns the JSON configuration status for CIS Control 10. Based on this output, what is the most immediate security implication for the listed assets?

Exhibit

{
  "control_id": "CIS_10",
  "action": "Enable_Full_Disk_Encryption",
  "status": "NON_COMPLIANT",
  "affected_assets": ["WS-001", "WS-004", "SRV-09"]
}

Your security team is implementing CIS Control 6: Access Control Management. Which TWO of the following tasks are explicitly required to fulfill the requirements of this control?

Which of the following frameworks is primarily considered a prescriptive set of prioritized actions to protect an organization from known cyber attack vectors?

Which THREE of the following activities are essential components of CIS Control 7: Continuous Vulnerability Management?

A logistics company is implementing CIS Control 4: Secure Configuration of Enterprise Assets and Software. Which two of the following activities are required to establish and maintain secure configurations? (Choose two.)

A retail company is implementing CIS Control 4: Secure Configuration of Enterprise Assets and Software. The IT team is reviewing the requirements to ensure they meet the control's intent. Which TWO of the following activities are explicitly required by CIS Control 4? (Choose two.)

Your organization is adopting the CIS Critical Security Controls to bolster defense. You are currently focused on establishing a secure baseline configuration for all workstation images. Which specific CIS Control should you prioritize to ensure that unauthorized software and unauthorized configuration changes are mitigated?

An organization is performing a gap analysis against the CIS Controls. They find that while they have strong identity management, they fail to track the software installed on local machines, leading to 'shadow IT.' Which CIS Control should they implement to address this specific visibility gap?

An organization is reviewing CIS Control 11: Data Recovery. Which of the following activities best demonstrates adherence to the 'testing' requirement of this control?

An organization is applying CIS Control 9: Email and Web Browser Protections. They have successfully implemented domain-based message authentication (DMARC). What is the primary security goal being achieved by this implementation?

A financial services firm is aligning its security program with the CIS Critical Security Controls. The CISO wants to ensure that the organization can measure the effectiveness of its security posture over time and prioritize improvements. Which of the following should the security team implement to achieve this?

A healthcare organization is implementing CIS Control 14: Security Awareness and Skills Training. The security manager needs to ensure that the training program effectively reduces phishing susceptibility among employees. Which of the following approaches best aligns with the control's requirements?

A financial services company is aligning its security program with the CIS Critical Security Controls. The CISO asks you to identify which Implementation Group (IG) is most appropriate for a small startup with limited IT staff that handles only publicly available data and has no regulatory compliance obligations. Which IG should you recommend?

A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?

A retail company is adopting the CIS Critical Security Controls and wants to prioritize its efforts. According to the CIS Controls, which of the following is the first basic control that should be implemented to gain visibility into assets?

A financial services firm has implemented all 18 CIS Critical Security Controls at Implementation Group 2. During a board presentation, the CISO is asked how the organization should measure the effectiveness of its security program. Which of the following best describes the role of Implementation Groups within the CIS Controls framework?

A university is implementing CIS Control 6: Access Control Management. They want to ensure that user accounts are properly managed. Which of the following actions best aligns with the requirement to manage the lifecycle of user accounts?

A healthcare provider is aligning its security program with the CIS Critical Security Controls. The security team is tasked with implementing CIS Control 1: Inventory and Control of Enterprise Assets. Which of the following activities is the most critical first step to ensure the control is effectively implemented?

A small marketing agency has limited IT staff and resources. They are looking to adopt a security framework to protect their assets. They have heard about the CIS Critical Security Controls and want to know which Implementation Group is most appropriate for their situation. Which of the following should they choose?

A multinational corporation is aligning its incident response program with the CIS Critical Security Controls. They are focusing on CIS Control 17: Incident Response Management. Which of the following activities best demonstrates the establishment of a formal incident response process as required by this control?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Frameworks and CIS Controls sessions

Start a Security Frameworks and CIS Controls only practice session

Every question in these sessions is drawn from the Security Frameworks and CIS Controls domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Security Frameworks and CIS Controls?
Be able to read a scenario, identify the applicable CIS Control or Implementation Group, and justify the choice by the safeguard's intent. The single most important thing: know that CIS Controls are prioritized by Implementation Group, with basic hygiene controls first.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Frameworks and CIS Controls questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Frameworks and CIS Controls domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.