Exam Mode

NIS 2 Directive Lead Implementer

Comply with the NIS 2 directive

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
D1 Fundamental concepts of the NIS 2 Directive78%
D4 Controls, incident and crisis management64%
D3 Roles, responsibilities and risk management55%
D2 Planning the NIS 2 implementation82%
D6 Testing and monitoring of the programme70%
D5 Communication and awareness61%

The domains assessed

Actual distribution of this product questions.

D1 Fundamental concepts of the NIS 2 Directive68
D4 Controls, incident and crisis management68
D3 Roles, responsibilities and risk management66
D2 Planning the NIS 2 implementation57
D6 Testing and monitoring of the programme57
D5 Communication and awareness44

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. D1 Fundamental concepts of the NIS 2 Directive

    NordEnergy's legal counsel asks the Lead Implementer why the NIS 2 Directive led to differing national rules across Member States, unlike some other EU cybersecurity instruments. Which explanation is correct?

    1. As a Regulation, the NIS 2 Directive applied directly in every Member State from its entry into force, so divergence was not possible.
    2. Being a Directive, it is non-binding guidance, so Member States were free to ignore it, which produced varied outcomes.
    3. As a Directive, it sets objectives that each Member State must achieve through its own national law, which explains why transposition and timing differ.
    4. Being a Directive, it applies uniformly and directly like the GDPR, leaving no discretion to Member States.
  2. D2 Planning the NIS 2 implementation

    Within the planning methodology for NIS 2 implementation, which statement best characterises the command-and-control regulatory approach?

    1. The regulator specifies only the desired security outcomes and leaves each entity free to choose the means of achieving them.
    2. An entity self-regulates through meaningful assessment and planning in order to set the goals that it will pursue.
    3. The regulator prescribes the exact methods, materials and processes that entities must use in order to comply.
    4. The entity and the regulator jointly negotiate voluntary targets that impose no binding obligation and are revised annually.
  3. D3 Roles, responsibilities and risk management

    Under Article 20 of the NIS 2 Directive, which obligation falls on the management bodies of essential and important entities?

    1. They must personally configure the technical security controls deployed across the network and information systems.
    2. They must notify the CSIRT of every significant incident within 24 hours of becoming aware.
    3. They must approve the cybersecurity risk-management measures and oversee their implementation.
    4. They must draft the national cybersecurity strategy in coordination with the competent authority.
  4. D4 Controls, incident and crisis management

    Under Article 21(1) of the NIS 2 Directive, what kinds of cybersecurity risk-management measures must essential and important entities put in place to protect their network and information systems?

    1. Appropriate and proportionate technical, operational and organisational measures.
    2. Only the measures mandated word for word in advance by the competent authority under a strict command-and-control model of regulation.
    3. Purely technical safeguards such as firewalls and encryption, since organisational and procedural controls fall outside the Directive's remit.
    4. Financial reserves and insurance cover sufficient to pay any administrative fine that a competent authority might later impose.
  5. D5 Communication and awareness

    Under the NIS 2 Directive, how are basic cyber hygiene practices and cybersecurity training treated within an entity's cybersecurity risk-management measures?

    1. As a minimum measure that essential and important entities must adopt under Article 21(2)(g).
    2. As an optional enhancement recommended only for essential entities operating in the energy sector.
    3. As a supervisory measure that competent authorities perform on entities under Article 32.
    4. As a reporting obligation that arises only after a significant incident under Article 23.
  6. D6 Testing and monitoring of the programme

    A Lead Implementer at NordEnergy is establishing policies and procedures to assess whether the entity's cybersecurity risk-management measures are actually working. Which provision of the NIS 2 Directive provides the direct legal basis for this testing and measurement activity?

    1. Article 23 on incident reporting obligations
    2. Article 21(2)(b) on incident handling measures
    3. Article 21(2)(f) on effectiveness assessment
    4. Article 20 on management-body governance and oversight
  7. D1 Fundamental concepts of the NIS 2 Directive

    A Lead Implementer is briefing FoodLine management on which EU instruments apply directly and which need transposition. Which statement is correct?

    1. DORA (Regulation (EU) 2022/2554) applies directly, whereas the NIS 2 Directive must be transposed into national law before it binds entities.
    2. The NIS 2 Directive applies directly across the Union, while DORA must be transposed by each Member State.
    3. Both the NIS 2 Directive and the GDPR are Regulations with direct effect throughout the Union.
    4. The NIS 2 Directive and DORA are both Directives that each Member State must transpose into national law.
  8. D2 Planning the NIS 2 implementation

    CloudNova, a cloud computing service provider, is established in three Member States: its board takes the decisions on cybersecurity risk-management measures in Ireland, its largest data centre operations run in Germany, and most of its Union workforce is employed in France. Under Article 26 of the NIS 2 Directive, which Member State has jurisdiction over CloudNova?

    1. Ireland, because a cloud computing service provider answers to the Member State of its main establishment, which is where the decisions related to the cybersecurity risk-management measures are predominantly taken.
    2. Germany, because for digital infrastructure providers the Member State in which the bulk of the cybersecurity operations are carried out takes precedence over the Member State in which the strategic decisions on those measures are taken.
    3. France, because the establishment with the highest number of employees in the Union is the first criterion Article 26 uses to locate the main establishment of a cloud computing service provider.
    4. All three Member States concurrently, because an entity falls under the jurisdiction of every Member State in which it is established and offers its services to users located on that territory.
  9. D3 Roles, responsibilities and risk management

    NordEnergy, an essential entity in the energy sector, has adopted cybersecurity risk-management measures. Under Article 20, what is the specific role of its management body regarding those measures?

    1. Approve the measures taken to comply with Article 21 and oversee their implementation.
    2. Delegate full accountability for the measures to the appointed competent authority.
    3. Limit its involvement to receiving an annual summary without any approval role.
    4. Transfer responsibility for the measures entirely to the entity's external suppliers.
  10. D4 Controls, incident and crisis management

    NordEnergy, an essential energy entity, is calibrating how far its cybersecurity risk-management measures must go. According to Article 21(1) and 21(2), which factors determine the appropriate depth of those measures?

    1. The market share held by the entity relative to its direct competitors within the same sector.
    2. Solely the total number of employees recorded on the entity's payroll at the close of the preceding financial year.
    3. The entity's degree of exposure to risk, its size, and the likelihood and severity of incidents including their societal and economic impact.
    4. Only the volume of personal data processed by the entity, mirroring the risk criteria that apply under the GDPR (Regulation (EU) 2016/679).

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the NIS 2 Directive Lead Implementer training.

See the training

All exams