Courseiva

CCNA Leadership And Organizational Management Questions

61 questions · Leadership And Organizational Management · All types, answers revealed

1
MCQmedium

When evaluating a third-party SaaS provider, which activity is most critical for assessing the vendor's security commitment?

A.Checking the vendor's marketing materials
B.Reviewing independent audit reports like SOC 2 Type II
C.Asking for the vendor's internal password policy
D.Verifying the vendor's office location
AnswerB

This is the industry standard for validating third-party security posture.

Why this answer

Reviewing independent audit reports (such as SOC 2 Type II) provides verified evidence of the vendor's controls, which is more reliable than self-assessments.

2
MCQmedium

Which of the following is the most important factor in the success of a security governance program?

A.The complexity of the security technology
B.Executive leadership support and commitment
C.The number of security staff members
D.The frequency of internal audits
AnswerB

Governance requires the mandate that only executive leadership can provide.

Why this answer

Executive leadership support is the foundation upon which the security program is built; without it, policies lack authority and resources remain scarce.

3
MCQeasy

A security manager is evaluating organizational security culture. Which indicator provides the most reliable evidence of a 'security-first' culture?

A.Volume of self-reported security near-misses
B.Budget allocated to security
C.Percentage of employees who completed training
D.Number of security policies written
AnswerA

This indicates an empowered and vigilant workforce.

Why this answer

The reporting of near-misses by employees shows that staff are actively engaged in security awareness and feel safe identifying potential threats, which is a key trait of a mature security culture.

4
MCQhard

An ISSMP needs to ensure compliance with global data privacy regulations in a multinational environment. Which governance strategy provides the most consistent approach?

A.Excluding high-risk regions from business operations
B.Maintaining separate policies for every country
C.Adopting the strictest regulatory standard as the global baseline
D.Relying on legal counsel to interpret local laws for every access request
AnswerC

This creates a unified, compliant, and manageable framework.

Why this answer

Implementing a global privacy framework that defaults to the strictest common denominator ensures compliance across all jurisdictions, simplifying operational management.

5
MCQmedium

A CISO is aligning the organizational information security strategy with the NIST Cybersecurity Framework (CSF) 2.0. Which specific function should the CISO prioritize to ensure that the organizational security culture promotes the identification of risks before they impact business operations?

A.Identify
B.Govern
C.Protect
D.Recover
AnswerB

The Govern function provides the oversight necessary to inform the organization's cybersecurity strategy and culture.

Why this answer

The 'Govern' function in NIST CSF 2.0 is specifically designed to establish the organizational context, risk management strategy, and cybersecurity supply chain risk management, which are foundational for aligning security culture with business objectives.

6
Multi-Selectmedium

Which TWO of the following are essential components of an effective security governance framework?

Select 2 answers
A.The latest artificial intelligence tools
B.Clearly defined roles, responsibilities, and accountability
C.Documented security policies and standards
D.A dedicated office space for the security team
E.A large annual security budget
AnswersB, C

This ensures that people are assigned to execute and uphold the policies.

Why this answer

A comprehensive framework needs defined policies (what) and a structure of accountability (who) to ensure execution.

7
MCQhard

An ISSMP is leading a strategic security planning initiative using the balanced scorecard approach. Which perspective should be used to track metrics related to the workforce's proficiency and security awareness training success?

A.Financial
B.Customer
C.Internal Business Processes
D.Learning and Growth
AnswerD

This perspective specifically tracks training, skills, and organizational culture.

Why this answer

In the balanced scorecard framework, the 'Learning and Growth' perspective focuses on the human capital, infrastructure, and culture necessary to achieve the organization's security goals.

8
Multi-Selectmedium

Which TWO of the following are primary components of an effective strategic security planning process as defined by (ISC)2 best practices for an ISSMP?

Select 2 answers
A.Alignment of security objectives with organizational business goals
B.Creating a daily incident report for the Board
C.Manual review of every individual firewall rule change
D.Purchasing the most expensive security software available
E.Conducting a gap analysis between current security maturity and target state
AnswersA, E

Fundamental for ensuring security supports rather than hinders business outcomes.

Why this answer

Strategic planning requires aligning security goals with business objectives and conducting a formal gap analysis to determine the current state versus the future state.

9
MCQmedium

An organization is expanding into a new region. What is the most important first step for the ISSMP?

A.Updating the corporate security policy
B.Deploying security monitoring tools
C.Conducting a regulatory and legal gap analysis
D.Hiring a local security manager
AnswerC

This provides the foundation for all subsequent security and compliance activities.

Why this answer

Conducting a regulatory and legal gap analysis ensures that the organization understands the compliance requirements of the new jurisdiction before initiating operations.

10
MCQmedium

A CISO is aligning security objectives with the enterprise's Balanced Scorecard. Which perspective should the CISO focus on to demonstrate the value of security investments in achieving organizational mission readiness?

A.Customer Perspective
B.Learning and Growth Perspective
C.Internal Process Perspective
D.Financial Perspective
AnswerC

This aligns security controls with the key internal operations needed to achieve mission objectives.

Why this answer

The Internal Process perspective of the Balanced Scorecard focuses on the processes at which the organization must excel to satisfy shareholders and customers, which directly links security program maturity to organizational mission readiness.

11
Multi-Selectmedium

Which TWO of the following are effective ways to promote a strong security culture?

Select 2 answers
A.Hiring more security staff
B.Establishing a 'blame-free' reporting environment for incidents
C.Mandating that all employees use a password manager
D.Publicly rewarding security-conscious behavior
E.Sending daily phishing emails to everyone
AnswersB, D

This encourages transparency and learning over secrecy.

Why this answer

Culture is driven by leadership example and the empowerment of employees to take ownership of security as a shared responsibility.

12
Multi-Selectmedium

Which TWO of the following are key responsibilities of the CISO regarding corporate risk management?

Select 2 answers
A.Aligning security controls with the enterprise risk appetite
B.Determining the organization's risk appetite
C.Hiring external penetration testers
D.Personally fixing every firewall misconfiguration
E.Reporting on residual risk to the board
AnswersA, E

Ensuring controls match the risk appetite is a primary CISO duty.

Why this answer

The CISO is responsible for translating technical risks into business impact and for ensuring that the organization's risk appetite is reflected in security controls.

13
MCQeasy

An ISSMP is conducting a security awareness program. What is the primary metric for measuring the success of this program?

A.The cost per employee for training
B.Number of training slides created
C.Percentage of employees who attended sessions
D.Change in behavior evidenced by incident reduction or simulation data
AnswerD

This directly reflects the effectiveness of the training.

Why this answer

A reduction in actual security incidents or improved response to simulated phishing tests are direct indicators of improved security behavior, which is the program's goal.

14
Multi-Selecthard

Which THREE of the following should be included in an annual strategic security plan?

Select 3 answers
A.Current state assessment of security maturity
B.Resource and budget requirements
C.A detailed list of every firewall rule
D.A list of all employee salaries
E.Proposed security projects and initiatives
AnswersA, B, E

You must understand where you are to plan where to go.

Why this answer

A strategic plan must look at current maturity, future initiatives (projects), and the resources required to achieve those goals.

15
MCQhard

The board of directors requests a quantitative risk assessment for a new cloud-based initiative. Which metric provides the best representation of potential financial exposure to the organization for a single, significant security event?

A.Single Loss Expectancy (SLE)
B.Residual Risk
C.Annualized Loss Expectancy (ALE)
D.Annualized Rate of Occurrence (ARO)
AnswerA

SLE is the direct product of the asset value and the exposure factor.

Why this answer

Single Loss Expectancy (SLE) is the monetary loss expected from a single security incident, making it the most direct metric for board-level financial exposure discussions.

16
Multi-Selecthard

Which THREE of the following are important considerations for an ISSMP when outsourcing security functions?

Select 3 answers
A.Retaining the ultimate accountability for security
B.Requiring the vendor to use only your internal tools
C.Defining clear Service Level Agreements (SLAs)
D.Verifying the provider's security compliance and capability
E.Choosing the vendor with the lowest price
AnswersA, C, D

The organization cannot outsource its legal and regulatory responsibility.

Why this answer

Outsourcing requires careful legal review, performance monitoring (SLAs), and ensuring that the provider is properly integrated into the organization's overall risk management.

17
MCQmedium

An organization is conducting a risk assessment and identifies a critical vulnerability in a legacy system that cannot be patched. Which of the following is the most appropriate risk management strategy to address this vulnerability?

A.Transfer the risk to a third-party vendor without further assessment.
B.Decommission the system immediately regardless of business impact.
C.Implement compensatory controls to reduce the risk.
D.Accept the risk without implementing any additional controls.
AnswerC

Compensatory controls are designed to mitigate risk when the primary control (patching) cannot be implemented.

Why this answer

When patching is not possible, implementing compensatory controls (such as network segmentation or enhanced monitoring) is the standard approach to reduce the residual risk to an acceptable level.

18
Multi-Selectmedium

When designing a security program, which TWO of the following factors should be considered to ensure the program can successfully scale with organizational growth?

Select 2 answers
A.Limiting the organization to only one type of operating system.
B.Designing security controls that are modular and can be easily integrated.
C.Requiring all security configurations to be manually audited daily.
D.Automating security controls and workflows to reduce manual overhead.
E.Maintaining all security data in a single, local spreadsheet.
AnswersB, D

Modular design allows for easier integration into new environments as the organization grows.

Why this answer

Scalability depends on automating processes where possible and ensuring the security architecture is modular and flexible to adapt to new business units or technologies.

19
Multi-Selecteasy

Which THREE of the following represent the primary responsibilities of executive leadership in fostering a strong organizational security culture?

Select 3 answers
A.Holding business units accountable for security outcomes
B.Writing technical documentation for network architecture
C.Installing software patches on all end-user workstations
D.Approving and supporting the security strategy and resource allocation
E.Modeling secure behavior and prioritizing security in decision-making
AnswersA, D, E

Ensures security is a shared responsibility across the organization.

Why this answer

Executive leadership is responsible for setting the tone, providing resources, and ensuring accountability, which directly shapes the security culture of the organization.

20
MCQmedium

When managing cross-functional security projects, which stakeholder communication strategy is most effective for securing project resources?

A.Focusing strictly on threat lists and vulnerability counts
B.Aligning security project outcomes with business goals
C.Escalating all requests to the CEO
D.Using technical jargon to emphasize the severity of risks
AnswerB

Demonstrating value in business terms is the most effective way to secure resources.

Why this answer

Linking security initiatives to business outcomes, such as reduced downtime or faster time-to-market, ensures that non-technical stakeholders understand the necessity of resource allocation.

21
MCQmedium

An ISSMP is implementing a Disaster Recovery (DR) plan. Which objective is most important to define with business leaders?

A.The total cost of the recovery site
B.The physical address of the secondary site
C.The names of the IT staff members
D.Recovery Time Objective (RTO)
AnswerD

RTO aligns the recovery plan with business continuity expectations.

Why this answer

Recovery Time Objective (RTO) defines the maximum acceptable downtime for a business service, which drives the design of the recovery infrastructure.

22
MCQmedium

When transitioning to an Agile development methodology, which security management approach best supports the 'Shift Left' security strategy?

A.Performing security audits only after deployment
B.Requiring manual sign-off for every code commit
C.Limiting access to the development environment
D.Integrating automated security testing in the CI/CD pipeline
AnswerD

Automation early in the pipeline is the cornerstone of the shift left strategy.

Why this answer

Integrating security activities (like threat modeling) into the design and development phases ensures vulnerabilities are identified and mitigated earlier in the lifecycle.

23
MCQhard

When establishing a security governance framework, what is the most critical element for ensuring long-term program success?

A.Ensuring the framework is fully automated.
B.Outsourcing security oversight to a third-party audit firm.
C.Securing ongoing executive sponsorship and clear accountability.
D.Selecting the most robust technical security tools available.
AnswerC

Governance must be driven from the top down to ensure it is integrated into the organization's culture and operations.

Why this answer

Executive sponsorship and clear accountability are the pillars of effective governance; without them, policies and frameworks lack the authority and resources needed for implementation.

24
MCQmedium

When reporting to the board of directors, which presentation method is most effective for communicating security performance?

A.A list of all blocked malicious IP addresses
B.Detailed technical logs and packet captures
C.Dashboards correlating security metrics to business objectives
D.A full copy of the latest penetration test report
AnswerC

This provides the strategic context relevant to the board.

Why this answer

Using dashboards with KPIs that correlate security activity to business objectives (e.g., risk reduction, compliance status) provides the context necessary for informed board decision-making.

25
MCQhard

When aligning security with organizational goals, how should an ISSMP address a conflict between security controls and user productivity?

A.Conduct a risk-benefit analysis for alternative controls
B.Remove the security control to favor productivity
C.Delegate the decision to the IT support manager
D.Enforce the security control regardless of impact
AnswerA

This finds the balance between protection and business functionality.

Why this answer

Conduct a risk-benefit analysis to determine if the security control is truly necessary and if alternative, less intrusive controls exist that provide the same level of protection.

26
MCQhard

A multinational organization needs to align its security policies with various regional privacy regulations (e.g., GDPR, CCPA). What is the best strategy to achieve this?

A.Create separate, unique security policies for every region.
B.Only comply with the regulations in the company's headquarters location.
C.Adopt a 'least common denominator' approach to security policies.
D.Establish a global baseline policy with region-specific supplements.
AnswerD

This balances global consistency with local regulatory compliance requirements.

Why this answer

Developing a global baseline policy that meets the most stringent requirements, supplemented by local addendums, ensures compliance while maintaining a unified security management approach.

27
MCQmedium

Your organization is evaluating the procurement of a new SaaS platform. As the ISSMP, you are responsible for integrating security into the vendor risk management process. Which action is most critical during the 'Due Diligence' phase?

A.Requesting the vendor's penetration test results from five years ago
B.Reviewing the vendor's SOC 2 Type II report for documented control effectiveness
C.Verifying the vendor's office location and physical building security
D.Ensuring the vendor signs a standard non-disclosure agreement
AnswerB

The SOC 2 Type II provides independent audit evidence of control operational effectiveness.

Why this answer

Reviewing the vendor's SOC 2 Type II report is the standard practice for verifying the effectiveness of security controls over a period of time, ensuring they meet organizational security requirements.

28
MCQhard

When managing a global security team, what is the primary challenge in maintaining a uniform security posture?

A.Lack of global email systems
B.Cultural differences and local regulations
C.Time zone differences
D.Language barriers
AnswerB

These require a flexible but principled governance approach.

Why this answer

Cultural differences and local regulatory requirements make it difficult to enforce a single, global standard, requiring a balance between global directives and local adaptation.

29
MCQeasy

A CISO needs to justify an increase in the security budget. Which argument is most persuasive to the Chief Financial Officer (CFO)?

A.Quantifying financial exposure from potential security events
B.Comparing the budget to industry peers
C.Focusing on the technical features of a new tool
D.Listing the latest security threats in the industry
AnswerA

CFOs understand financial risk management and ROI.

Why this answer

Quantifying the cost of potential data breaches in terms of lost revenue and regulatory fines demonstrates the financial risk the CFO is helping to manage.

30
MCQhard

An organization wants to improve its security posture against supply chain attacks. Which action is most effective for an ISSMP?

A.Outsourcing all IT functions to a single large provider
B.Implementing a third-party risk management program
C.Replacing all proprietary software with open-source
D.Increasing internal network segmentation
AnswerB

TPRM addresses the security posture of the vendors and suppliers.

Why this answer

Implementing a third-party risk management (TPRM) program that assesses vendors' security practices is the best way to address risks introduced by the supply chain.

31
MCQhard

As a Chief Information Security Officer (CISO), you need to ensure that the security program is aligned with organizational business objectives. Which activity best demonstrates this alignment?

A.Aligning security projects and resource allocation with business objectives.
B.Focusing primarily on technical vulnerabilities and patch management.
C.Adopting the latest security technologies regardless of current business needs.
D.Establishing a comprehensive security policy and enforcing it strictly.
AnswerA

Strategic alignment ensures that security investments support and enable business operations and risk tolerance.

Why this answer

Mapping security initiatives to business goals demonstrates the direct impact and value of the security program, which is crucial for executive buy-in and resource allocation.

32
MCQmedium

When managing a security incident, what is the primary role of the CISO in a large enterprise?

A.Updating firewall rules manually
B.Performing forensic analysis on the compromised server
C.Ensuring communication and strategic coordination
D.Drafting the initial incident response report
AnswerC

The CISO manages the impact and external organizational requirements.

Why this answer

The CISO should focus on strategic decision-making, stakeholder communication, and resource management, leaving the tactical investigation to the incident response team.

33
MCQmedium

Which leadership style is most effective for building a strong security team during a period of rapid organizational growth?

A.Transformational leadership
B.Transaction-based leadership
C.Laissez-faire leadership
D.Autocratic leadership
AnswerA

This builds engagement and long-term capability.

Why this answer

Transformational leadership inspires the team, fosters innovation, and aligns individual efforts with the broader security vision, which is essential during times of change.

34
Multi-Selectmedium

Which TWO of the following are metrics that provide insight into the effectiveness of security leadership?

Select 2 answers
A.Number of firewall blocks per second
B.Trend in risk reduction over time
C.Return on security investment (ROSI)
D.The color of the security team's uniforms
E.The number of security certifications held by the CISO
AnswersB, C

This demonstrates the impact of strategic security investments.

Why this answer

Leadership effectiveness is best measured by the organization's ability to minimize risk over time and the efficiency with which resources are converted into security posture improvements.

35
Multi-Selecthard

Which THREE of the following are challenges in transitioning to a secure DevSecOps model?

Select 3 answers
A.Using only manual security review processes
B.Lack of security training for developers
C.Cultural resistance from development teams
D.Difficulty in automating security testing without breaking builds
E.Replacing all developers with security professionals
AnswersB, C, D

Developers need to understand security to write secure code.

Why this answer

Transitioning requires overcoming cultural resistance, automating complex security gates, and ensuring developers have the right training to take ownership of security.

36
MCQeasy

A security manager is drafting a security policy. Which element is essential for ensuring executive support and establishing the policy's organizational authority?

A.A list of vendors
B.A list of all employees
C.Detailed technical configuration standards
D.Executive sponsorship and signature
AnswerD

This establishes the mandate and commitment required for enterprise-wide compliance.

Why this answer

An executive signature or sponsorship is required to demonstrate that the policy has the backing of the organization's leadership and is not just a departmental suggestion.

37
MCQeasy

As an ISSMP, you are defining the organizational security culture. Which activity is the most effective way to demonstrate executive commitment to security?

A.Sending an automated email newsletter regarding password policies
B.Appointing a dedicated Security Awareness Officer
C.Actively chairing the cross-functional Security Steering Committee
D.Increasing the budget for the security operations center
AnswerC

Executive presence in leadership forums demonstrates that security is a top-tier business concern.

Why this answer

The tone at the top is the most significant factor in shaping security culture. Direct executive participation in security steering committees signals that security is a business priority.

38
MCQmedium

A CISO is presenting a security program roadmap. Which approach is best for managing expectations regarding security maturity?

A.Linking maturity to the total security budget
B.Promising 100% security coverage by the end of the year
C.Focusing only on the latest security technologies
D.Defining security maturity as a set of phased milestones
AnswerD

Phased milestones provide transparency and realistic goal-setting.

Why this answer

Providing a phased implementation plan with measurable milestones allows the CISO to demonstrate progress while acknowledging that maturity is a journey.

39
MCQeasy

An organization wants to improve its security posture by adopting a continuous monitoring approach. Which approach is most effective for an ISSMP to champion?

A.Implementing integrated security telemetry and automated analysis.
B.Relying on manual logs review on a monthly basis.
C.Implementing a firewall with default deny rules.
D.Conducting annual penetration tests.
AnswerA

This approach enables real-time visibility and faster response to emerging threats, which is central to continuous monitoring.

Why this answer

Continuous monitoring requires integrated data collection, automated analysis, and real-time reporting to provide actionable insights, which is the definition of a robust monitoring strategy.

40
Multi-Selecthard

Which THREE of the following are key indicators of a mature security governance program?

Select 3 answers
A.The board receives regular, meaningful updates on security posture
B.Security metrics are tied to clear business KPIs
C.Security risks are integrated into the enterprise risk management (ERM) process
D.The security team works in total isolation from the rest of the company
E.The CISO reports to the Help Desk manager
AnswersA, B, C

Active oversight by the board is a hallmark of maturity.

Why this answer

Mature programs are characterized by metrics-driven processes, integration with enterprise functions, and active, informed oversight by the board.

41
Multi-Selectmedium

Which TWO of the following are core components of a business-aligned security strategy?

Select 2 answers
A.A requirement for all employees to have PhDs
B.Prioritization of security investments based on business impact
C.A complete list of every software vulnerability in the firm
D.A mandate that all security tools must be from one vendor
E.Identification of business-critical assets and processes
AnswersB, E

This ensures the most significant risks are addressed first.

Why this answer

Alignment requires understanding the business's current state and risk profile, and ensuring that security projects are prioritized to support the most important business functions.

42
MCQhard

A CISO is managing a security budget with high pressure for cost optimization. Which strategy provides the best balance between security and cost efficiency?

A.Delaying all security projects by 12 months
B.Reducing headcount in security operations
C.Implementing risk-based resource allocation
D.Switching to only open-source security tools
AnswerC

This ensures investments are directed where they provide the most protection.

Why this answer

Risk-based resource allocation allows the security team to prioritize investments on the highest-impact threats, ensuring maximum ROI on security spending.

43
Multi-Selecthard

An ISSMP is developing a cross-functional incident response team. Which THREE roles or functions are absolutely critical to include to ensure comprehensive handling of a major security breach?

Select 3 answers
A.Legal Counsel (General Counsel or Privacy Officer).
B.External janitorial staff for physical security.
C.Executive leadership representative (C-Suite).
D.Public Relations / Corporate Communications.
E.Internal cafeteria staff for onsite catering.
AnswersA, C, D

Legal is essential for handling regulatory notifications, liability, and evidence handling.

Why this answer

A major incident requires more than just technical response; it requires legal oversight, communication strategies, and executive decision-making capabilities.

44
MCQhard

To ensure security requirements are integrated into the System Development Life Cycle (SDLC), what is the most effective approach for the security team?

A.Embedding security champions within development teams
B.Requiring developers to attend annual security seminars
C.Automating the code deployment process
D.Mandating a security review before production release
AnswerA

This allows for continuous security advocacy and integration.

Why this answer

Embed security champions within development teams to act as liaisons, ensuring security is considered throughout the development process rather than treated as a final check.

45
MCQmedium

Which organizational structure is most effective for a CISO to influence security behavior across geographically dispersed and independent business units?

A.Centralized Command and Control
B.Outsourced Security Operations
C.Matrix Management
D.Decentralized/Siloed Management
AnswerC

Provides the balance of authority and influence needed in large, complex organizations.

Why this answer

A matrix management structure allows the CISO to exert influence through both functional and operational lines, ensuring security standards are consistent while respecting business unit autonomy.

46
MCQmedium

An organization is migrating to a hybrid cloud environment and is updating its security architecture. Which of the following is the MOST effective way to ensure consistent security policy enforcement across both on-premises and cloud environments?

A.Managing separate security policies for on-premises and cloud environments.
B.Prioritizing the security of on-premises assets over cloud assets.
C.Allowing individual departments to define their own security policies.
D.Implementing a unified security policy framework across all environments.
AnswerD

A unified policy framework provides a consistent set of rules and controls, which simplifies management and auditing while reducing the risk of configuration errors.

Why this answer

Implementing a unified security policy framework ensures that security requirements are standardized and consistently applied regardless of the underlying infrastructure. This approach reduces complexity and human error in policy management.

47
MCQeasy

Which document establishes the high-level security objectives and the roles/responsibilities of senior management within an organization?

A.Standard Operating Procedure (SOP)
B.Security Charter
C.Acceptable Use Policy (AUP)
D.Incident Response Plan
AnswerB

This defines the purpose and authority of the security function.

Why this answer

The Security Charter or Security Governance Framework outlines the scope, mandate, and leadership roles required to oversee the security program.

48
MCQeasy

During a cross-functional security planning session, the IT operations team argues that security controls are negatively impacting system performance. As an ISSMP, what is the most appropriate management approach to resolve this conflict?

A.Perform a joint business impact analysis to determine the optimal balance of security and performance
B.Enforce the security controls regardless of performance impacts
C.Escalate the issue to the CIO for a final decision without further analysis
D.Reduce security controls until performance targets are met
AnswerA

A BIA allows all stakeholders to quantify the risk and make a consensus-based decision.

Why this answer

Effective security management involves balancing security needs with business operational requirements through a collaborative risk-based approach, ensuring security is integrated rather than imposed.

49
MCQhard

An organization is adopting a Zero Trust Architecture (ZTA). Which management principle is critical for the long-term success of this transition?

A.Continuous monitoring and verification
B.Centralized static access lists
C.Automated patch management only
D.Strict perimeter-based defense
AnswerA

ZTA relies on the assumption that no user or device is inherently trusted.

Why this answer

Continuous monitoring and verification are the fundamental principles of ZTA; without them, the architecture cannot adapt to changing threat landscapes.

50
Multi-Selectmedium

When presenting a security budget request to the Board of Directors, which THREE of the following elements should be included to ensure the request is compelling and understood?

Select 3 answers
A.A summary of the latest cybersecurity job market trends.
B.A comprehensive analysis of the return on investment (ROI) or risk-reduction value.
C.Alignment of the investment with specific business risk reduction goals.
D.A clear articulation of the potential business impact of failing to act.
E.Detailed list of every firewall rule and server configuration.
AnswersB, C, D

Demonstrating the value of the spend is essential for executive approval.

Why this answer

Board members prioritize risk-based arguments over technical jargon. They need to understand the impact on business outcomes, the current risk level, and the return on investment (or cost of inaction).

51
Multi-Selecthard

Which THREE of the following are critical for successfully managing cross-functional security initiatives?

Select 3 answers
A.Demonstrating clear alignment with business benefits
B.Early and active involvement of key stakeholders
C.Focusing solely on the technical specifications
D.Excluding IT management from the planning phase
E.Establishing shared accountability for security outcomes
AnswersA, B, E

Business leaders are more likely to support initiatives that help them reach their goals.

Why this answer

Success in cross-functional work requires stakeholder involvement, clear communication of the business value, and shared ownership of the outcomes.

52
Multi-Selecthard

Which THREE of the following are common indicators that a security program is failing to align with business objectives?

Select 3 answers
A.Increase in unauthorized technology use (Shadow IT)
B.Employees consistently bypassing security controls
C.Security budget is lower than the IT budget
D.The security team is located in the basement
E.Lack of visibility or support from senior leadership
AnswersA, B, E

This shows that business units are solving problems without IT/security approval.

Why this answer

Lack of executive support, high levels of friction, and shadow IT are all strong indicators of a disconnect between security strategy and business goals.

53
MCQhard

An ISSMP is evaluating a Cloud Access Security Broker (CASB) implementation. Which management goal is most effectively addressed by this tool?

A.Automating the patching of local workstations
B.Managing user access to local databases
C.Enforcing security policies for cloud application usage
D.Securing the physical data center
AnswerC

CASB is specifically designed to bridge the visibility gap in cloud environments.

Why this answer

A CASB provides visibility and control over cloud usage, enabling the enforcement of corporate security policies on data stored or accessed in cloud applications.

54
MCQmedium

Which of the following is the most important factor to consider when evaluating the effectiveness of a security training and awareness program?

A.Measurable improvements in employee behavior and incident reporting.
B.The total budget allocated to security awareness programs.
C.The frequency and quality of security awareness training sessions.
D.The number of employees who completed the training modules.
AnswerA

The primary goal of security awareness is to reduce human risk, which is best measured by behavioral changes.

Why this answer

Behavioral changes, such as reduced click rates on phishing simulations and increased reporting of suspicious activities, are the best indicators of a successful security awareness program.

55
Multi-Selectmedium

Which TWO of the following are effective communication strategies for a CISO interacting with senior executives?

Select 2 answers
A.Focusing on the business impact of security risks
B.Providing hour-long technical deep dives on every vulnerability
C.Presenting data in a clear, actionable format
D.Using complex, obscure security acronyms
E.Writing 50-page reports for every meeting
AnswersA, C

This connects security to the executive's world.

Why this answer

Executives need concise, business-focused information that allows them to make informed decisions about risk and resource allocation.

56
MCQhard

An ISSMP is managing a merger where two organizations use different identity providers. Which strategy best mitigates identity-related risk during the integration phase?

A.Granting domain administrative rights to both IT teams
B.Implementing a federated identity solution
C.Migrating all users to a new identity provider immediately
D.Creating duplicate user accounts for all employees
AnswerB

Federation provides a secure, scalable way to manage cross-organizational identities.

Why this answer

Establishing a federated identity model allows for centralized management and consistent access control policies across both entities without forcing an immediate migration.

57
MCQeasy

Which of the following is a key component of a successful security awareness training program?

A.Focusing only on threats to external users
B.Regular, engaging, and relevant content
C.Using outdated training videos to save costs
D.Mandating attendance once every five years
AnswerB

This ensures the message is understood and remembered.

Why this answer

Regular, relevant, and engaging content is necessary to keep security top-of-mind for employees and to ensure long-term retention of good security practices.

58
MCQmedium

You are reviewing the organization's Incident Response Plan (IRP). According to the NIST SP 800-61 framework, which phase requires the highest level of coordination between legal, human resources, and IT departments?

A.Detection and Analysis
B.Post-Incident Activity
C.Preparation
D.Containment, Eradication, and Recovery
AnswerD

This phase necessitates the most complex multi-departmental decision-making during an active event.

Why this answer

The 'Containment, Eradication, and Recovery' phase requires intense cross-functional coordination, especially when legal and HR involvement is needed for evidence preservation or employee-related policy enforcement.

59
Multi-Selecthard

As an ISSMP developing a security governance program, which THREE of the following activities are essential to ensure the program remains effective and compliant?

Select 3 answers
A.Directly managing all firewall configurations manually
B.Establishing a formal security steering committee
C.Assigning clear roles and responsibilities for security tasks
D.Reviewing security policy compliance through regular audits
E.Increasing the number of help desk tickets handled daily
AnswersB, C, D

Provides the governance structure and oversight required.

Why this answer

Governance requires continuous monitoring, clear policy oversight, and defined accountability structures, which are achieved through these three activities.

60
MCQeasy

What is the primary purpose of an Incident Response (IR) plan?

A.To identify all vulnerabilities in the network
B.To punish employees who cause incidents
C.To replace the need for security policies
D.To provide a structured approach to incident handling
AnswerD

Standardization ensures efficiency and reduces panic during incidents.

Why this answer

An IR plan provides a structured, predefined approach to handling security incidents to minimize impact and ensure business continuity.

61
MCQhard

An organization is moving from a reactive security posture to a proactive threat-informed defense. As the ISSMP, you are implementing the MITRE ATT&CK framework. Which executive-level metric best demonstrates the maturity of the security program to the Board of Directors regarding this transition?

A.Time to remediate critical security incidents
B.Percentage of MITRE ATT&CK techniques covered by existing controls
C.Number of phishing emails blocked by the email gateway
D.Total number of vulnerabilities patched per month
AnswerB

This metric directly ties the security program's capabilities to real-world adversary behaviors.

Why this answer

Mapping security coverage to MITRE ATT&CK techniques provides a quantifiable measure of defensive maturity that boards can understand, representing the shift from reactive compliance to proactive threat management.

Ready to test yourself?

Try a timed practice session using only Leadership And Organizational Management questions.