CSL CSL Workforce Development & Security Culture 2 — Questions and Answers
Question 1: A CISO wants to establish a security operations center (SOC). Which staffing model provides the best balance of control and cost efficiency?
- Fully outsourced Managed Security Service Provider (MSSP)
- Hybrid model combining internal SOC analysts with MSSP support (Correct answer)
- Fully in-house SOC with no external partnerships
- Rotating IT help desk staff through SOC duties
Correct answer: Hybrid model combining internal SOC analysts with MSSP support
A hybrid SOC model retains internal ownership of critical functions while leveraging MSSP resources for 24/7 coverage and specialized expertise.
Question 2: Which framework provides a structured approach for defining cybersecurity team roles and responsibilities?
- RACI matrix aligned to NIST CSF functions (Correct answer)
- Agile sprint planning model
- ISO 9001 quality management system
- ITIL change management process
Correct answer: RACI matrix aligned to NIST CSF functions
A RACI matrix mapped to NIST CSF functions (Identify, Protect, Detect, Respond, Recover) clearly defines who is Responsible, Accountable, Consulted, and Informed for each security function.
Question 3: What role does psychological safety play in a high-performing cybersecurity team?
- It is irrelevant to technical security work
- It encourages team members to report mistakes and share threat intelligence without fear (Correct answer)
- It reduces the need for formal incident reporting processes
- It allows team members to bypass security controls
Correct answer: It encourages team members to report mistakes and share threat intelligence without fear
Psychological safety enables security team members to report near-misses, mistakes, and emerging threats without fear of punishment, improving overall threat visibility.
Question 4: What is the primary goal of succession planning within a cybersecurity leadership program?
- To comply with HR department requirements only
- To ensure continuity of security leadership when key personnel depart (Correct answer)
- To identify underperforming employees for replacement
- To automate security decision-making processes
Correct answer: To ensure continuity of security leadership when key personnel depart
Succession planning identifies and develops future leaders to prevent leadership gaps that could weaken the security program during transitions.
Question 5: A security leader wants to measure team performance in the SOC. Which KPI most directly reflects operational effectiveness?
- Number of security tools deployed
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) (Correct answer)
- Total alerts generated per day
- Number of security patches applied
Correct answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
MTTD and MTTR measure how quickly threats are identified and contained, directly reflecting the SOC's ability to minimize the impact of incidents.
Question 6: Which approach helps close the cybersecurity skills gap within an organization most cost-effectively?
- Only recruiting from external talent markets
- Upskilling existing IT employees through targeted training and certification programs (Correct answer)
- Outsourcing all security functions to third parties
- Reducing security team headcount and automating all tasks
Correct answer: Upskilling existing IT employees through targeted training and certification programs
Developing existing IT staff with cybersecurity training and certifications is faster and less expensive than competing for scarce external cybersecurity talent.
A CISO wants to establish a security operations center (SOC).
Which staffing model provides the best balance of control and cost efficiency?