PECB-NIS2-LI Sample Questions & Answers
Most of the questions target planning the NIS 2 Directive's governance and rollout, the single biggest weight, plus compliance testing, awareness training, basic NIS 2 concepts and related frameworks, risk management, and handling incidents and crises.
Launch the full PECB-NIS2-LI simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Cybersecurity controls, incident management, and crisis management · Significant incident reporting
During a review of a draft incident response plan for an 'essential entity', the lead implementer notes that the plan triggers reporting to the national CSIRT only for incidents that have resulted in confirmed data exfiltration. Why is this plan non-compliant with the NIS 2 Directive's definition of a 'significant incident'?
Show answer & explanation
Correct answer: B
Article 23(3) defines a 'significant incident' as one that either causes or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, OR affects or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. By focusing only on data exfiltration, the plan ignores the critical criterion of operational disruption, which is a key trigger for reporting under NIS 2.
- Question 2Intermediate
Testing and monitoring of a cybersecurity program · Performance indicators and monitoring
An organization is setting up a program to monitor its NIS 2 compliance. The management body requires a dashboard with Key Performance Indicators (KPIs). Which of the following would be the LEAST effective KPI for demonstrating the effectiveness of the cybersecurity risk management program to the management body?
Show answer & explanation
Correct answer: B
The number of trouble tickets is an operational metric that can be influenced by many factors (e.g., new system rollouts, user error, minor issues). It does not directly measure the effectiveness of risk management in preventing significant incidents. A high number could even indicate better user reporting. The other options are much better indicators of risk reduction, control effectiveness, and response capability.
- Question 3Beginner
Communication and awareness · Management body training
A public administration body in a Member State is considered an 'essential entity'. It is undergoing a NIS 2 implementation and needs to establish a cybersecurity training program for its management body. What is the primary objective of this training as mandated by the NIS 2 Directive?
Show answer & explanation
Correct answer: C
Article 20 of the NIS 2 Directive requires that members of the management bodies follow training. The goal is not for them to become technical experts, but to equip them with the necessary knowledge to fulfill their oversight responsibilities. This includes being able to identify cybersecurity risks and assess the adequacy of the organization's risk-management practices and their implications for the services provided.
- Question 4Intermediate
Cybersecurity roles and responsibilities and risk management · Risk treatment and supply chain
A lead implementer is conducting a risk assessment for a digital marketplace platform, which is an 'important entity'. The assessment identifies a critical risk related to a third-party payment gateway provider. The provider has suffered breaches in the past. What is the most appropriate risk treatment strategy in alignment with NIS 2's focus on supply chain security?
Show answer & explanation
Correct answer: D
NIS 2 places strong emphasis on managing supply chain security (Article 21). While risk acceptance, transference (insurance), and avoidance are valid strategies, they are not the primary approach for a critical, ongoing third-party dependency. Mitigation through active security management—including contractual obligations, due diligence (assessments), and joint planning—is the most comprehensive and compliant strategy to manage the risk associated with a critical supplier.
- Question 5IntermediateSelect 3
Planning of NIS 2 Directive requirements implementation · Scoping the compliance program
When planning the implementation of NIS 2 requirements for a cross-border healthcare provider, the lead implementer must define the scope of the compliance program. Which elements are essential to define in this scoping phase? (Select THREE)
Show answer & explanation
Correct answers: A, C, D
- Question 6Advanced
Cybersecurity controls, incident management, and crisis management · Incident classification and reporting
Case Study: EuroRail Freight
Company Background: EuroRail Freight operates a critical rail freight network across four EU Member States and is an 'essential entity'. Their core operations depend on a centralized digital signaling and train control system. They have a mature IT security team that manages corporate systems, but the signaling system is managed by a specialized engineering team.
Incident: A sophisticated phishing campaign targets the engineering team. An engineer's credentials are compromised, giving an attacker access to a maintenance laptop that can connect to the signaling system's management network. The attacker manipulates signaling data, causing minor but widespread train delays for several hours before the anomaly is detected and access is revoked. The incident causes significant economic disruption for EuroRail's customers but does not lead to any physical accidents or data breaches.
Response: The team contains the incident and restores normal service within 8 hours. They immediately begin an internal investigation. The Head of Engineering believes that since no data was breached and no one was hurt, this is a minor operational issue, not a reportable cybersecurity incident.
Question: As the NIS 2 Lead Implementer advising EuroRail, what is the correct guidance regarding their reporting obligations under Article 23?
Show answer & explanation
Correct answer: B
The NIS 2 Directive's definition of a 'significant incident' explicitly includes any incident that 'has caused or is capable of causing severe operational disruption of the services'. Widespread train delays on a critical freight network constitute a severe operational disruption. Therefore, the incident is reportable. The first step is submitting an early warning within 24 hours to the relevant CSIRT or competent authority.
- Question 7Intermediate
Planning of NIS 2 Directive requirements implementation · Vulnerability disclosure policy
A lead implementer is developing a coordinated vulnerability disclosure policy for a software development company that falls under NIS 2 as a managed service provider. Which of the following is a key component that should be included in this policy, according to cybersecurity best practices?
Show answer & explanation
Correct answer: C
A robust coordinated vulnerability disclosure policy, aligned with standards like ISO/IEC 29147, must provide clear channels for reporting, set expectations for communication and remediation timelines, and include a 'safe harbor' clause to assure researchers they will not face legal action for good-faith efforts that adhere to the policy. This encourages responsible disclosure. Bug bounties are optional, and immediate public disclosure is irresponsible.
- Question 8Intermediate
Fundamental concepts and definitions of NIS 2 Directive · Supervision and enforcement
True or False: An entity classified as 'important' under the NIS 2 Directive is subject to the same proactive, regular supervisory checks by competent authorities as an 'essential' entity.
Show answer & explanation
Correct answer: B
False. The NIS 2 Directive establishes a differentiated approach to supervision. 'Essential entities' are subject to proactive supervision, including regular audits and inspections. 'Important entities' are subject to reactive (ex-post) supervision, meaning authorities will investigate only when they have evidence of non-compliance, such as after a significant incident is reported.
- Question 9Beginner
Testing and monitoring of a cybersecurity program · Role of CSIRTs
A Member State's national CSIRT is tasked with monitoring threats and incidents at a national level as part of its NIS 2 responsibilities. To fulfill this role effectively, what is a key requirement for the CSIRT's capabilities?
Show answer & explanation
Correct answer: B
Article 11 of the NIS 2 Directive outlines the tasks of CSIRTs. A fundamental capability for monitoring and responding is the ability to communicate effectively. This includes maintaining secure and resilient communication channels to receive incident reports from entities and to disseminate alerts and advisories to stakeholders. While they analyze threats and support entities, issuing fines is typically the role of the competent authority, not the CSIRT.
- Question 10Intermediate
Communication and awareness · Information sharing arrangements
As part of an information sharing arrangement under Article 29 of NIS 2, a group of energy companies decides to share threat intelligence. To be effective and compliant, this sharing must primarily be conducted in a way that:
Show answer & explanation
Correct answer: A
Article 29 encourages voluntary cybersecurity information-sharing arrangements. The directive specifies that such sharing is meant to enhance the level of cybersecurity, in particular by raising awareness, exchanging best practices, and sharing information on threats, near misses, vulnerabilities, and tools. Therefore, the information must be timely and practical to be of value. The sharing must also respect data protection rules and business confidentiality.
Ready for the real thing?
The full PECB-NIS2-LI simulator has every exam-style question, timed mode, and instant scoring.