Free ISC2 Certified in Cybersecurity practice — 6 questions on Security Principles, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 1: Security Principles
A mid-size hospital purchases a cyber-insurance policy that will pay out up to $2,000,000 to cover incident response costs, legal fees, and regulatory fines in the event of a data breach. The hospital does not change any technical or administrative controls as a result of this purchase. Which risk treatment strategy has the hospital applied?
Purchasing insurance shifts the financial impact of a risk to a third party (the insurer) without reducing the likelihood or impact of the event itself — this is the textbook definition of risk transfer.
Question 2 of 6 · Domain 1: Security Principles
An organization implements digital signatures on all outgoing executive emails so that a sender cannot later deny having sent a specific message, and recipients can cryptographically verify the sender's identity. Which security principle is being PRIMARILY addressed?
Non-repudiation ensures that a party in a communication cannot falsely deny having sent or received data; digital signatures are the classic mechanism for proving origin and preventing denial of authorship.
Question 3 of 6 · Domain 1: Security Principles
A CISO drafts a formal, board-approved document stating: 'All company data must be classified and protected according to its sensitivity level. Compliance is mandatory for all employees.' No specific technical settings or step-by-step actions are included. What TYPE of governance document is this?
A policy is a high-level, mandatory statement of management intent that sets overall direction and requires compliance, but does not prescribe specific technical implementation details — exactly what's described.
Question 4 of 6 · Domain 1: Security Principles
A data center requires visitors to be escorted by an authorized employee at all times and uses mantrap doors requiring a badge swipe followed by a biometric scan before entering the server room. Which category of control does this represent?
Physical controls are tangible measures that protect the physical environment — mantraps, badge readers, escorts, and biometric door locks are all physical security mechanisms restricting physical access to a facility.
Question 5 of 6 · Domain 1: Security Principles
According to the ISC2 Code of Ethics, all members must adhere to four mandatory canons. Which of the following is listed FIRST in priority order among the canons?
The ISC2 Code of Ethics lists its four canons in a specific priority order, and 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' is explicitly the first and highest-priority canon.
Question 6 of 6 · Domain 1: Security Principles
A risk assessment determines that a particular threat has a LOW likelihood of occurring but, if it did occur, would cause a CATASTROPHIC impact that could bankrupt the company (e.g., total loss of the only data center with no backups). Using standard qualitative risk analysis (likelihood x impact), which risk treatment is MOST appropriate for this scenario?
Qualitative risk analysis considers both likelihood AND impact together — a low-likelihood event with catastrophic (extremely high) impact still yields significant overall risk, so mitigation (e.g., building redundancy/backups) or transfer (e.g., insurance) is the appropriate treatment rather than simple acceptance.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.