The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 40 |
| 2 | Domain training | 40 |
| 3 | Domain training | 40 |
| 4 | Domain training | 40 |
| 5 | Timed simulation | 40 |
| 6 | Timed simulation | 40 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
Domain 1: Fundamental principles and concepts of cybersecuri
Halvorsen Web Services, a 120-person hosting company, is renewing contracts with two banking clients. Both now require an independent third-party certificate attesting that Halvorsen manages information security systematically. The security team has spent a month studying ISO/IEC 27032, because most of Halvorsen's risks concern Internet-facing services. Which approach meets the clients' requirement?
- Implement ISO/IEC 27032 and seek certification against it, as it addresses Internet security directly
- Have an ISMS certified to ISO/IEC 27001, using ISO/IEC 27032 as guidance on Internet-facing risks
- Adopt the CIS Controls and give the clients a self-assessment of the implementation group reached
- Apply the ISO/IEC 27002 controls and give the clients an external consultant's gap analysis report
-
Domain 2: Risk management and cybersecurity controls
Ardent Freight, a haulier with 900 employees, suffered two ransomware attacks last year that stopped its dispatch operations for three days each. The newly appointed CISO is drafting the company's cybersecurity objectives and has copied the objective list of a widely recognized framework, which covers compliance, stakeholder confidence and asset protection. She asks a colleague to review how the objectives were determined. What should the colleague recommend?
- Submit the framework's list to the board for validation as it stands
- Rework the objectives using those adopted by a peer haulier of similar size
- Rework the objectives using the dispatch outages and incidents of last year
- Keep the list and map each objective to the controls of that framework
-
Domain 1: Fundamental principles and concepts of cybersecuri
Brightwater Analytics, a private US company, has won a contract to operate a grants management system on behalf of a federal civilian agency. The system belongs to the agency and processes controlled unclassified information. Brightwater's compliance lead proposes building the security programme for this system on NIST SP 800-171, because Brightwater is a private contractor. Which security requirements should govern this system?
- The SP 800-53 controls, since the agency's system falls under FISMA whoever operates it
- The SP 800-171 requirements, since a contractor is protecting controlled unclassified information
- The CSF 2.0 outcomes, since a private company adopts the framework on a voluntary basis
- The DFARS safeguarding clauses, since a defence contractor is handling covered information
-
Domain 2: Risk management and cybersecurity controls
Velmora Diagnostics, a medical laboratory with 300 staff, runs an online results service that 40 partner clinics use to decide on patient treatment. Internally, the corporate email system has the largest number of users, and the billing system holds the most financial data. With a limited budget, the security manager must decide which service to strengthen first. What should guide the decision?
- Prioritize the results service, since partner clinics depend on it for their treatment decisions
- Prioritize the corporate email system, since it connects staff with clinics, suppliers and patients
- Prioritize the billing system, since insurers and patients depend on its invoices being accurate
- Prioritize the systems the latest scan rated most exposed, since attackers are likely to target them
-
Domain 1: Fundamental principles and concepts of cybersecuri
Corvane Logistics completed a project last year that aligned its security practices with NIST guidelines, and an external review confirmed the alignment. During budget planning, the CFO proposes cancelling the quarterly employee security training, arguing that the company is now compliant and no further effort is needed. The CISO must respond at the next management meeting. The external reviewer had recommended an annual compliance review to confirm that the alignment holds. What should the CISO recommend?
- Cancel the sessions and rely on the signed policies, which set out each person's duties
- Keep the quarterly training sessions funded in next year's budget, as they are today
- Replace the sessions with an annual compliance review, as security must be monitored regularly
- Keep the training for new employees, whose awareness the alignment project last year did not cover
-
Domain 2: Risk management and cybersecurity controls
After a reorganization, Kellford County's public works agency must designate a senior agency information security officer to manage information security across the agency. The agency head reminds the management team that she is ultimately accountable for ensuring adequate safeguards. The authorizing official and the risk executive function have also been appointed. Which role is responsible for designating the senior agency information security officer?
- The agency head, who carries ultimate responsibility for the agency's information security
- The Chief Information Officer, who develops and maintains the agency's security policies
- The authorizing official, who accepts the security risk of operating agency systems
- The risk executive function, which oversees security risk across the agency as a whole
-
Domain 1: Fundamental principles and concepts of cybersecuri
Meridale Health's patient portal was interconnected last month with the system of a partner laboratory, and laboratory staff now log in from the laboratory's own network to upload test results. The portal's system owner has hardened the portal's boundary and reviewed its firewall rules. The laboratory now asks how the portal is protected before it extends the connection. The portal team believes that a hardened boundary is the best answer to any partner's concerns. What should the portal's system owner do?
- Ask the laboratory to sign an acceptable use agreement before its staff extend their use of the portal
- Refer the laboratory to the incident response team, which handles security duties towards other organizations
- Give the laboratory a description of the safeguards applied to the portal and to its interconnection
- Leave the laboratory responsible for its side and keep the work focused on protecting the portal's boundary
-
Domain 2: Risk management and cybersecurity controls
Pemberton Insurance, a private company, is creating a payroll administrator position with access to the salary and bank details of its 1,200 employees. Before the vacancy is advertised, management must decide what level of background check the position requires. Pemberton's physical security staff manage badges and guards, and its privacy office handles data protection compliance. The CISO, who previously worked for a government agency, recalls that physical security staff ran the checks there. Which supporting role assists in determining this requirement?
- Physical security staff, who develop security measures for facilities and handle clearances in government
- The payroll system owner, who decides which users need access to the salary and bank data
- Human resources, who set out the screening that each new post calls for before hiring
- The privacy office, who oversee compliance when personal data about candidates is collected and used
-
Domain 1: Fundamental principles and concepts of cybersecuri
At Tessaro Foods, the board has just approved the company's cybersecurity risk management strategy and its cybersecurity policy, and has assigned roles, responsibilities and authorities to the CISO and the heads of the business units. The chair explains that these decisions will help management understand and prioritize the company's cybersecurity risks. No assets have been inventoried yet. Under NIST CSF 2.0, which Function do these outcomes belong to?
- Govern (GV)
- Identify (ID)
- Protect (PR)
- Respond (RS)
-
Domain 2: Risk management and cybersecurity controls
Halden Media has noticed that several employees have installed peer-to-peer file-sharing applications on company laptops. The company already has a high-level general policy and a high-level specific policy on access to information and technology infrastructure. Management wants a document that tells employees how to proceed with peer-to-peer applications to keep the company secure. The legal team suggests a high-level specific policy, since the subject concerns one area. What type of policy should be written?
- A high-level specific policy on P2P use
- A clause in the high-level general policy
- A system security plan for the laptops
- A topic-specific policy on P2P use
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the NIST Cybersecurity Foundation training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.