CTO Cybersecurity Strategy & Governance 4 — Questions and Answers
Question 1: A CTO must align cybersecurity investments with business objectives. Which approach BEST achieves this?
- Maximize the security budget regardless of business risk
- Perform risk-based prioritization tying security spend to business-critical asset protection (Correct answer)
- Implement every available security control uniformly across all assets
- Delegate all security investment decisions to the CISO alone
Correct answer: Perform risk-based prioritization tying security spend to business-critical asset protection
Risk-based prioritization ensures security investments are proportional to the business value of assets and the likelihood and impact of threats against them.
Question 2: What distinguishes a security policy from a security standard?
- Policies are technical documents; standards are management documents
- Policies state high-level intent and requirements; standards define specific mandatory controls (Correct answer)
- Standards are aspirational; policies are legally binding
- Policies apply to IT staff only; standards apply to all employees
Correct answer: Policies state high-level intent and requirements; standards define specific mandatory controls
Policies establish high-level principles and requirements, while standards provide specific, mandatory technical or procedural controls that implement policy intent.
Question 3: Which security testing method simulates an attack from someone with no prior knowledge of the system?
- White-box testing
- Gray-box testing
- Black-box testing (Correct answer)
- Red team exercise
Correct answer: Black-box testing
Black-box testing simulates an external attacker with no prior knowledge of internal systems, architecture, or source code.
Question 4: A company stores customer payment data. Which compliance standard is MOST directly applicable?
- SOC 2 Type II
- ISO 27001
- PCI DSS (Correct answer)
- HIPAA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) specifically governs the storage, processing, and transmission of cardholder data.
Question 5: What is the PRIMARY goal of a cybersecurity tabletop exercise?
- Testing technical security controls under live attack conditions
- Training responders and identifying gaps in incident response plans through simulated scenarios (Correct answer)
- Auditing compliance with security policies
- Evaluating the performance of security monitoring tools
Correct answer: Training responders and identifying gaps in incident response plans through simulated scenarios
Tabletop exercises walk participants through simulated incident scenarios to test decision-making, communication, and identify gaps in response procedures without disrupting operations.
Question 6: Which security architecture concept involves running applications in isolated environments to limit the blast radius of a compromise?
- Network segmentation
- Sandboxing (Correct answer)
- Data masking
- Key management
Correct answer: Sandboxing
Sandboxing isolates application execution environments so that a compromise of one application cannot directly impact other systems or data.
Question 7: A CTO receives a board request to demonstrate cybersecurity maturity. Which tool is MOST appropriate?
- A CVSS score report for known vulnerabilities
- A Cybersecurity Maturity Model Certification (CMMC) or similar maturity framework assessment (Correct answer)
- The number of security incidents in the past year
- A list of security tools currently deployed
Correct answer: A Cybersecurity Maturity Model Certification (CMMC) or similar maturity framework assessment
Maturity model assessments like CMMC or the NIST CSF maturity tiers provide a structured, benchmarkable view of organizational security capabilities appropriate for board-level reporting.
A CTO must align cybersecurity investments with business objectives.
Which approach BEST achieves this?