Exam Mode

NIST Cybersecurity Lead Implementer

Implement a cybersecurity program based on the NIST framework

NIST Cybersecurity
Lead Implementer
6 exams · 480 questions · 5 domains

The six exams, one by one

ExamFormatQuestions
1Domain training80
2Domain training80
3Domain training80
4Domain training80
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
D2 Planning and organizational strategy in cybersecurity78%
D3 Implementing a cybersecurity program and security control64%
D5 Cybersecurity incident response55%
D1 Fundamental principles and concepts of cybersecurity82%
D4 Cybersecurity incident management70%

The domains assessed

Actual distribution of this product questions.

D2 Planning and organizational strategy in cybersecurity150
D3 Implementing a cybersecurity program and security control132
D5 Cybersecurity incident response90
D1 Fundamental principles and concepts of cybersecurity60
D4 Cybersecurity incident management48

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. D1 Fundamental principles and concepts of cybersecurity

    A regional transit operator is adding track-side IoT sensors and moving its ticketing platform to a cloud service. Its risk manager proposes writing a separate risk management process for each technology. The chief architect, who led the original RMF rollout for the on-premises servers, objects that no new process is needed because the RMF keeps the controls selected to protect each kind of system unchanged, so the servers' approved control set can simply be copied to the sensors and the cloud platform. The sensors send only temperature readings, while the ticketing platform processes payment card data. Under SP 800-37 Rev. 2, what does the RMF keep unchanged across all three kinds of system?

    1. The controls selected to protect each kind of system
    2. The impact level assigned to each kind of system
    3. The steps and tasks followed to manage each system's risk
    4. The methods and objects used to assess each system's controls
  2. D2 Planning and organizational strategy in cybersecurity

    A retailer is choosing a National Checklist Program checklist for its internet-facing web server, which stores customer payment records and is probed by attackers every day. The server sits in the corporate data center and is administered centrally with the other servers. It serves only current browsers, and no older systems depend on it. For which operational environment should the selected checklist be written?

    1. Stand-Alone, for devices that users administer on their own
    2. Managed (Enterprise), for devices administered through central policy
    3. Specialized Security-Limited Functionality, for restricted devices
    4. Legacy, for devices that depend on older communication mechanisms
  3. D4 Cybersecurity incident management

    A state breach notification law signed this week, in mid-February, takes effect on April 1 and shortens the time allowed to notify affected individuals. The organization reviews its incident response policy and procedures every May. An internal audit of incident response is under way, with its report due at the end of April, and the compliance officer suggests waiting for it so that all changes are made at once. The post-incident review of a January phishing incident, notified under the old law, is scheduled for June. When should the policy and procedures be reviewed and updated?

    1. At the scheduled review in May
    2. Before the end of March
    3. When the audit report is issued in late April
    4. At the post-incident review in June
  4. D3 Implementing a cybersecurity program and security control

    A water treatment plant's control system relies on a historian component whose vendor stopped issuing patches last year. The plant's OT security manager, a veteran of two utilities, recommends isolating the historian from networks outside the plant's control, as he did at his previous employer. The board has approved a budget to replace it, but no product yet works with the plant's equipment, and the plant has no developers able to build its own fixes. Under its operating permit, the historian sends hourly compliance readings to the state regulator's internet portal. A company that maintains discontinued industrial software has quoted an annual agreement covering security fixes for this historian version. The system supports a critical mission function. How should the plant address the risk from the unsupported component?

    1. Replace the historian with a currently supported product
    2. Isolate the historian from networks outside the plant's control
    3. Contract the specialist firm for continued historian support
    4. Develop in-house patches for the historian's critical flaws
  5. D5 Cybersecurity incident response

    During recovery from a ransomware outage at a county office, a system administrator is stopped outside the building by a local journalist asking whether property records were lost. The county's crisis communications plan designates the communications director, Helen Price, as the only media contact, with her deputy, Owen Burke, as the alternate when she is unavailable. Helen is on leave this week. The legal counsel, Nadia Hart, reviews draft statements, and the recovery is led by the IT manager, Carl Novak, who knows the facts best. What should the administrator do?

    1. Refer the journalist to Helen Price without comment
    2. Refer the journalist to Owen Burke without comment
    3. Refer the journalist to Nadia Hart without comment
    4. Refer the journalist to Carl Novak without comment
  6. D1 Fundamental principles and concepts of cybersecurity

    Case study 1 - Harbor Point Water Authority (5 questions) Harbor Point Water Authority is a municipal utility with 900 staff, three treatment plants and a central operations center. The board has asked the new CISO, Dana Whitfield, to turn a draft CSF 2.0 Current Profile into a funded program within twelve months. The risk register lists eleven moderate risks; four of them affect different plants but all depend on the same SCADA support vendor, while the other seven are unrelated to one another. The approved hardening budget covers about 40% of the 2,300 inventoried assets, and the latest scan ranks the office print servers, used by all staff, highest for critical findings; all of the authority's data carries one internal classification. Luis Ortega, a plant engineer, moved to finance in March but is still on the access list for the Plant 2 control room, which is reviewed every December; the plant manager confirms he has no duties left there, not even on-call cover. Lakeview Springs, a 30-person district utility absorbed in June, will keep running its own systems; only its manager has IT duties and sees no need for written security roles in so small an organization. The authority's role document names role holders at its three plants only. Operations wants 600 wireless water-quality sensors next year; the budget line exists, but no vendor has been shortlisted. Question 1 of 5: Luis Ortega says he still visits Plant 2 to help former colleagues at shift changes and asks to keep his badge so that he can be called in an emergency. What should happen to his authorization for the Plant 2 control room?

    1. Remove his Plant 2 authorization and disable his accounts, as for a departure
    2. Restrict his authorization to escorted entry and log each visit at the plant
    3. Keep his authorization and record him as emergency cover for Plant 2
    4. Remove his name from the Plant 2 access list and revoke the credential
  7. D2 Planning and organizational strategy in cybersecurity

    A hospital group must buy core routers for its clinical network, and three vendors answered the market survey. The incumbent, which passed a full supplier risk assessment last month, offers a steep discount for a sole-source renewal of its current router line; that line reaches end of support next year. The state health department publishes a qualified products list for firewalls, but none for routers of this class. Procurement proposes a 'lowest price, technically acceptable' award with security features in the technical threshold. Which source selection approach should the hospital group use?

    1. A lowest price award, with supply chain criteria as a technical threshold
    2. A sole-source award, with supply chain risk weighed in the renewal terms
    3. A best-value award, with supply chain risk scored among the award factors
    4. A best-value award, with supply chain risk screened through a qualified products list
  8. D4 Cybersecurity incident management

    A managed security service provider hired for detection and response shut down an organization's customer portal at 02:00 to contain suspected malware, without consulting anyone. The next morning the CIO protests that the provider 'had no authority to act for us' and asks for a clause spelling out the provider's authority. The contract in fact already authorizes the provider to act on the organization's behalf to contain threats, binds it to a non-disclosure clause on incident data, and lists on-call contacts reachable around the clock. What should the contract have defined in advance to prevent what happened at 02:00?

    1. The provider's authority to act for the organization, such as isolating hosts
    2. Restrictions on the provider's operational decisions, such as taking a service offline
    3. The provider's confidentiality duties, such as a non-disclosure clause on incident data
    4. Restrictions on the provider's sharing, such as sanitized details given to other clients
  9. D3 Implementing a cybersecurity program and security control

    A cloud engineering firm of 14 staff plans to assess Account Management (AC-2) once a year as a single block. Its platform team introduces new types of service and workload accounts almost every month, while staff transfers and departures happen about once a year. Inactive accounts are disabled automatically by the directory service. Which monitoring plan fits this control?

    1. Account types monthly, transfer removals quarterly, inactivity disabling by automated monitoring
    2. Account types yearly, transfer removals monthly, inactivity disabling by automated monitoring
    3. Account types monthly, transfer removals monthly, inactivity disabling by yearly review
    4. Account types yearly, transfer removals yearly, inactivity disabling by automated monitoring
  10. D5 Cybersecurity incident response

    Owners validated a company's restored systems yesterday, the systems have now run normally for 24 hours, and the after-action report has been drafted. The service manager, backed by the CIO, proposes to declare recovery ended once an owner and a date are set for the host records, since the entries for two compromised hosts still lack their containment times. The recovery plan lists three criteria for declaring the end of incident recovery: owner validation of restored systems, 24 hours of normal operation, and complete incident records. What should the incident lead decide?

    1. Declare recovery ended now and complete the host records in the lessons learned review
    2. Keep recovery open until the records of the two hosts have been completed
    3. Keep recovery open until the lessons learned are built into the plans
    4. Declare recovery ended once an owner and a date are set for the host records

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the NIST Cybersecurity Lead Implementer training.

See the training

All exams