The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 50 |
| 2 | Domain training | 50 |
| 3 | Domain training | 50 |
| 4 | Domain training | 50 |
| 5 | Timed simulation | 80 |
| 6 | Timed simulation | 80 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
D1 Fundamental concepts of the NIS 2 Directive
NordEnergy's legal counsel asks the Lead Implementer why the NIS 2 Directive led to differing national rules across Member States, unlike some other EU cybersecurity instruments. Which explanation is correct?
- As a Regulation, the NIS 2 Directive applied directly in every Member State from its entry into force, so divergence was not possible.
- Being a Directive, it is non-binding guidance, so Member States were free to ignore it, which produced varied outcomes.
- As a Directive, it sets objectives that each Member State must achieve through its own national law, which explains why transposition and timing differ.
- Being a Directive, it applies uniformly and directly like the GDPR, leaving no discretion to Member States.
-
D2 Planning the NIS 2 implementation
Within the planning methodology for NIS 2 implementation, which statement best characterises the command-and-control regulatory approach?
- The regulator specifies only the desired security outcomes and leaves each entity free to choose the means of achieving them.
- An entity self-regulates through meaningful assessment and planning in order to set the goals that it will pursue.
- The regulator prescribes the exact methods, materials and processes that entities must use in order to comply.
- The entity and the regulator jointly negotiate voluntary targets that impose no binding obligation and are revised annually.
-
D3 Roles, responsibilities and risk management
Under Article 20 of the NIS 2 Directive, which obligation falls on the management bodies of essential and important entities?
- They must personally configure the technical security controls deployed across the network and information systems.
- They must notify the CSIRT of every significant incident within 24 hours of becoming aware.
- They must approve the cybersecurity risk-management measures and oversee their implementation.
- They must draft the national cybersecurity strategy in coordination with the competent authority.
-
D4 Controls, incident and crisis management
Under Article 21(1) of the NIS 2 Directive, what kinds of cybersecurity risk-management measures must essential and important entities put in place to protect their network and information systems?
- Appropriate and proportionate technical, operational and organisational measures.
- Only the measures mandated word for word in advance by the competent authority under a strict command-and-control model of regulation.
- Purely technical safeguards such as firewalls and encryption, since organisational and procedural controls fall outside the Directive's remit.
- Financial reserves and insurance cover sufficient to pay any administrative fine that a competent authority might later impose.
-
D5 Communication and awareness
Under the NIS 2 Directive, how are basic cyber hygiene practices and cybersecurity training treated within an entity's cybersecurity risk-management measures?
- As a minimum measure that essential and important entities must adopt under Article 21(2)(g).
- As an optional enhancement recommended only for essential entities operating in the energy sector.
- As a supervisory measure that competent authorities perform on entities under Article 32.
- As a reporting obligation that arises only after a significant incident under Article 23.
-
D6 Testing and monitoring of the programme
A Lead Implementer at NordEnergy is establishing policies and procedures to assess whether the entity's cybersecurity risk-management measures are actually working. Which provision of the NIS 2 Directive provides the direct legal basis for this testing and measurement activity?
- Article 23 on incident reporting obligations
- Article 21(2)(b) on incident handling measures
- Article 21(2)(f) on effectiveness assessment
- Article 20 on management-body governance and oversight
-
D1 Fundamental concepts of the NIS 2 Directive
A Lead Implementer is briefing FoodLine management on which EU instruments apply directly and which need transposition. Which statement is correct?
- DORA (Regulation (EU) 2022/2554) applies directly, whereas the NIS 2 Directive must be transposed into national law before it binds entities.
- The NIS 2 Directive applies directly across the Union, while DORA must be transposed by each Member State.
- Both the NIS 2 Directive and the GDPR are Regulations with direct effect throughout the Union.
- The NIS 2 Directive and DORA are both Directives that each Member State must transpose into national law.
-
D2 Planning the NIS 2 implementation
CloudNova, a cloud computing service provider, is established in three Member States: its board takes the decisions on cybersecurity risk-management measures in Ireland, its largest data centre operations run in Germany, and most of its Union workforce is employed in France. Under Article 26 of the NIS 2 Directive, which Member State has jurisdiction over CloudNova?
- Ireland, because a cloud computing service provider answers to the Member State of its main establishment, which is where the decisions related to the cybersecurity risk-management measures are predominantly taken.
- Germany, because for digital infrastructure providers the Member State in which the bulk of the cybersecurity operations are carried out takes precedence over the Member State in which the strategic decisions on those measures are taken.
- France, because the establishment with the highest number of employees in the Union is the first criterion Article 26 uses to locate the main establishment of a cloud computing service provider.
- All three Member States concurrently, because an entity falls under the jurisdiction of every Member State in which it is established and offers its services to users located on that territory.
-
D3 Roles, responsibilities and risk management
NordEnergy, an essential entity in the energy sector, has adopted cybersecurity risk-management measures. Under Article 20, what is the specific role of its management body regarding those measures?
- Approve the measures taken to comply with Article 21 and oversee their implementation.
- Delegate full accountability for the measures to the appointed competent authority.
- Limit its involvement to receiving an annual summary without any approval role.
- Transfer responsibility for the measures entirely to the entity's external suppliers.
-
D4 Controls, incident and crisis management
NordEnergy, an essential energy entity, is calibrating how far its cybersecurity risk-management measures must go. According to Article 21(1) and 21(2), which factors determine the appropriate depth of those measures?
- The market share held by the entity relative to its direct competitors within the same sector.
- Solely the total number of employees recorded on the entity's payroll at the close of the preceding financial year.
- The entity's degree of exposure to risk, its size, and the likelihood and severity of incidents including their societal and economic impact.
- Only the volume of personal data processed by the entity, mirroring the risk criteria that apply under the GDPR (Regulation (EU) 2016/679).
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the NIS 2 Directive Lead Implementer training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.