EXAMINATION TEST 2026 QUESTIONS
WITH SOLUTIONS
◉ Which of the following best describes the similarities or differences
between the NIST RMF and the NIST CSF? Select two.
Components of the NIST RMF include respond and recover.
Both include a component to help assess and manage risks.
They are the result of state and industry-specific regulations.
They define tiers based on how well vulnerabilities are addressed.
Components of the NIST CSF include protect and detect. Answer: They
define tiers based on how well vulnerabilities are addressed.
Components of the NIST CSF include protect and detect.
Explanation: The National Institute of Standards and Technology
(NIST) profiles include the NIST Risk Management Framework (RMF)
and the NIST Cybersecurity Framework (CSF). They allow
organizations to see their vulnerabilities at each step; once the
vulnerabilities are mitigated, the organization can move up to higher
implementation tiers. The CSF is used as a measuring stick against
which companies can compare their cybersecurity practices relative to
the threats they face. The elements of the CFS include identify, protect,
detect, respond, and recover.
◉ When analyzing a security breach, Acer determines the attacker was
able to change the price of an item from $200 to $20. What security
protection was compromised?
, Confidentiality
Integrity
Authorization
Authentication Answer: Integrity
Explanation: Integrity ensures that the information is correct and no
unauthorized person or malicious software has altered the data. An
attacker changing data, such as the price of an item, violates the integrity
of the data.
◉ Which of the following best describes what Della could do to prevent
unauthorized parties from viewing sensitive customer information at her
retail store?
Use software to encrypt data in a secure database.
Verify the ID of the party requesting access to the data.
Limit access to certain areas once access is granted.
Ensure the data cannot be manipulated or changed. Answer: Use
software to encrypt data in a secure database.
Explanation: Confidentiality ensures that only authorized parties can
view the information. Providing confidentiality can involve several
different security tools such as using software to encrypt credit card
numbers stored on the web server or in a database, for example.
◉ To bypass institutional overhead, a well-intentioned networking
instructor purchases a wireless router and connects it to the network. The
goal is to allow students to establish connectivity with each other by
connecting through the wireless router. In what activity did the instructor
participate?