GRC IT Governance and Cybersecurity 2 — Questions and Answers
Question 1: Which COBIT 5 principle states that IT governance should address the needs of all stakeholders, not just the IT department?
- Meeting stakeholder needs (Correct answer)
- Covering the enterprise end-to-end
- Applying a single integrated framework
- Enabling a holistic approach
Correct answer: Meeting stakeholder needs
The 'Meeting Stakeholder Needs' principle ensures governance creates value by balancing benefits, risk, and resource use across all stakeholders.
Question 2: An organization wants to measure the effectiveness of its cybersecurity controls. Which metric best reflects the mean time to detect a security incident?
- MTTD (Mean Time to Detect) (Correct answer)
- MTTR (Mean Time to Respond)
- RTO (Recovery Time Objective)
- RPO (Recovery Point Objective)
Correct answer: MTTD (Mean Time to Detect)
MTTD measures the average time between when an incident occurs and when it is identified by the security team.
Question 3: Under NIST SP 800-53, which control family specifically addresses security planning at the organizational level?
- Planning (PL) (Correct answer)
- Program Management (PM)
- Risk Assessment (RA)
- System and Services Acquisition (SA)
Correct answer: Planning (PL)
The Planning (PL) control family in NIST SP 800-53 covers system security plans and rules of behavior.
Question 4: A company's board requires quarterly cybersecurity reports. Which governance artifact best satisfies this requirement?
- Security scorecard with KPIs and KRIs (Correct answer)
- Penetration test technical report
- Vulnerability scan raw output
- Security operations runbook
Correct answer: Security scorecard with KPIs and KRIs
A security scorecard summarizing KPIs and KRIs translates technical metrics into business-relevant information for board-level audiences.
Question 5: Which IT governance framework is specifically designed for IT service management and aligns IT services with business needs?
- ITIL (Correct answer)
- COBIT
- ISO 27001
- TOGAF
Correct answer: ITIL
ITIL (Information Technology Infrastructure Library) provides best practices for IT service management to align IT services with business requirements.
Question 6: In cybersecurity governance, what does a 'tone at the top' primarily influence?
- Security culture and employee behavior (Correct answer)
- Technical firewall configurations
- Patch management schedules
- Network segmentation design
Correct answer: Security culture and employee behavior
Tone at the top refers to leadership attitudes that shape organizational security culture and how seriously employees treat security policies.
Question 7: Which document formally defines the cybersecurity responsibilities of third-party vendors and their obligations to protect organizational data?
- Third-Party Risk Management Agreement / Vendor Contract (Correct answer)
- System Security Plan (SSP)
- Business Impact Analysis (BIA)
- Continuity of Operations Plan (COOP)
Correct answer: Third-Party Risk Management Agreement / Vendor Contract
Third-party risk management agreements or vendor contracts legally bind vendors to specific cybersecurity obligations and data protection requirements.
Which COBIT 5 principle states that IT governance should address the needs of all stakeholders, not just the IT department?