CTO Cybersecurity Strategy & Governance 5 — Questions and Answers
Question 1: What is the MOST significant cybersecurity risk introduced by shadow IT?
- Increased software licensing costs
- Unvetted systems outside security controls creating unknown attack surfaces (Correct answer)
- Slower IT service delivery to business units
- Duplication of existing approved tools
Correct answer: Unvetted systems outside security controls creating unknown attack surfaces
Shadow IT creates unmanaged systems that bypass security controls, vulnerability patching, and monitoring, introducing unknown and unmanaged attack surfaces.
Question 2: Which encryption standard is currently recommended by NIST for protecting sensitive US government data?
- DES
- 3DES
- AES-256 (Correct answer)
- RC4
Correct answer: AES-256
NIST recommends AES-256 as the encryption standard for protecting sensitive and classified government information due to its strength against known attacks.
Question 3: A CTO wants to establish a security culture organization-wide. What is the MOST effective long-term approach?
- Conducting a one-time mandatory security training for all employees
- Implementing continuous security awareness programs reinforced by leadership behavior (Correct answer)
- Increasing penalties for security policy violations
- Publishing monthly security newsletters
Correct answer: Implementing continuous security awareness programs reinforced by leadership behavior
Sustained security culture requires continuous reinforcement through ongoing training, simulations, and visible leadership commitment rather than one-time interventions.
Question 4: What does 'cyber resilience' add beyond traditional cybersecurity?
- Stronger perimeter defenses to prevent all breaches
- The ability to anticipate, withstand, recover from, and adapt to adverse cyber events (Correct answer)
- Faster vulnerability patching cycles
- More comprehensive security audits
Correct answer: The ability to anticipate, withstand, recover from, and adapt to adverse cyber events
Cyber resilience extends beyond prevention to encompass the organization's ability to maintain operations and recover quickly when security controls fail.
Question 5: Which role is PRIMARILY responsible for classifying data assets in a data governance framework?
- IT Security team
- Data owner (business unit leader) (Correct answer)
- Chief Compliance Officer
- Database administrator
Correct answer: Data owner (business unit leader)
Data owners, typically business unit leaders, are responsible for classifying data based on its business value and sensitivity, while IT implements the technical controls.
Question 6: A CTO discovers the organization's software supply chain was compromised through a trusted vendor update. Which mitigation is MOST relevant?
- Blocking all automatic software updates
- Implementing Software Bill of Materials (SBOM) and code signing verification (Correct answer)
- Replacing all vendor software with open-source alternatives
- Conducting more frequent penetration tests
Correct answer: Implementing Software Bill of Materials (SBOM) and code signing verification
SBOMs provide transparency into software components and dependencies, while code signing verification ensures updates originate from legitimate sources, directly addressing supply chain risks.
Question 7: When building a cybersecurity roadmap, what should a CTO prioritize FIRST?
- Acquiring the latest security technology tools
- Assessing the current security posture and identifying gaps against business risk (Correct answer)
- Achieving full compliance with all applicable regulations
- Hiring additional security personnel
Correct answer: Assessing the current security posture and identifying gaps against business risk
A gap assessment against current business risk provides the factual baseline needed to prioritize roadmap investments and justify resource allocation rationally.
What is the MOST significant cybersecurity risk introduced by shadow IT?