The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 40 |
| 2 | Domain training | 40 |
| 3 | Domain training | 40 |
| 4 | Domain training | 40 |
| 5 | Timed simulation | 40 |
| 6 | Timed simulation | 40 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
Domain 1: Fundamental concepts and definitions of NIS 2
A ransomware payload reached the file server of a company but was blocked by the endpoint protection before any file was encrypted and before any service became unavailable. Under the terminology of the Directive, how should this event be classified?
- An incident, because a malicious payload reached a production server
- A near miss, because the compromise was stopped before it materialised
- A significant incident, because ransomware can cause severe disruption
- A vulnerability, because the server was reachable by the payload
-
Domain 2: Planning of NIS 2 requirements implementation
The board of a covered entity signs off the cybersecurity risk-management measures and then leaves execution entirely to the IT department, without any further involvement. Which duty of the management body is being missed?
- Drafting the technical specifications of each measure before it is deployed
- Handing its legal liability down to the head of the department that executes the work
- Certifying the entity against an international management system standard
- Monitoring the way in which the approved measures are actually put into practice
-
Domain 1: Fundamental concepts and definitions of NIS 2
Which change did the current Directive introduce in comparison with the network and information security Directive of 2016?
- Notification opens with a preliminary alert that precedes the formal report
- Only events that produced measurable harm have to be brought to the authorities
- Feedback from the authorities to the notifying entity was removed to save time
- Sector coverage was narrowed to the critical infrastructure operators listed in 2016
-
Domain 2: Planning of NIS 2 requirements implementation
A regional postal operator is required by its supervisor to determine for itself what its exposure is, to fix its own targets and to submit the resulting document for review, instead of following a prescribed list of technologies. Which regulatory approach is being applied?
- Command and control, because a public body reviews what the operator produces
- Performance-based, because the outcome standards are fixed and the means are free
- Management-based, because the entity self-regulates and the regulator then evaluates
- Co-regulation by binding instruction, because the supervisor keeps the final word
-
Domain 1: Fundamental concepts and definitions of NIS 2
A company that produces and distributes electricity in one Member State employs 480 people and reports an annual turnover of 210 million euros. How is it classified?
- Important entity, because the supply of electricity appears in the annex that lists the other critical sectors
- Essential entity, because it goes beyond the ceilings of a medium-sized undertaking in a sector of high criticality
- Important entity, because the two ceilings that define a medium-sized undertaking have not both been exceeded
- Essential entity, because every undertaking active in the energy sector holds that status whatever its size or turnover
-
Domain 2: Planning of NIS 2 requirements implementation
A project team has to establish how cybersecurity is currently managed in an organisation whose employees claim that nothing is in place. Which combination of actions is recommended at that stage?
- Observing the controls in place on site, interviewing those in charge, reading the documentation held and reviewing past audit findings
- Commissioning an external penetration test of the main systems, alongside a vulnerability scan, and treating that report as the whole picture
- Postponing every form of data collection until the risk assessment is complete, so that the main risks are known before anyone is questioned
- Accepting the statement of the staff at face value, since they work with the systems daily, and recording an absence of any measure in place
-
Domain 1: Fundamental concepts and definitions of NIS 2
Which part of the legal text supplies the background and the interpretive guidance that help a reader understand the binding requirements, without imposing a requirement itself?
- The articles, which are numbered and grouped into chapters
- The annexes, which are organised into sectors and subsectors
- The recitals, which are numbered paragraphs placed before the enacting terms
- The correlation table, which maps the repealed provisions onto the current ones
-
Domain 2: Planning of NIS 2 requirements implementation
Who has to endorse the cybersecurity objectives of a compliance programme, and may those objectives still change once the work has started?
- The project manager endorses them, and they stay fixed until the programme is closed
- The supervisory authority endorses them, and they may be revised only at its request
- The internal audit function endorses them, and they are revised after each audit cycle
- The highest level of the organisation endorses them, and they may be revised as work progresses
-
Domain 1: Fundamental concepts and definitions of NIS 2
An entity already certified against the management system standard for information security asks which document will give it a reference set of generic controls together with guidance on putting them in place. Which one should it be pointed to?
- ISO/IEC 27002, usable within a management system or on its own as a basis of good practice
- ISO/IEC 27005, usable to satisfy the requirements on addressing information security risks
- ISO/IEC 27701, usable as an extension covering the management of privacy information
- ISO 22301, usable to protect against disruptions and to recover once they have arisen
-
Domain 2: Planning of NIS 2 requirements implementation
A team preparing an analysis of the context of an organisation wants a single tool that separates what comes from inside the organisation from what comes from its environment. Which tool does that by design?
- Porter's Five Forces, which weighs the rivalry between competitors, the buyers, the suppliers, the potential entrants and the substitutes
- SWOT analysis, whose strengths and weaknesses cover internal issues while opportunities and threats cover external ones
- PEST analysis, which reviews the political, economic, social and technological forces at work
- The maturity scale, which rates each process from nonexistent to optimised
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the NIS 2 Directive Foundation training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.