Free CPA ISC (Information Systems & Controls) Security, Confidentiality and Privacy Practice Questions

Security, confidentiality, and privacy on the CPA ISC exam tests cybersecurity frameworks (NIST), access control mechanisms, encryption standards, incident response procedures, data privacy regulations (GDPR, CCPA), and IT risk assessment methodologies.

404 Questions
186 Easy
149 Medium
69 Hard
2026 Syllabus

Sample Questions

Question 1 Easy
Which authentication factor category does a fingerprint scan belong to?
Solution
B is correct.

A fingerprint scan is a biometric authentication factor classified as 'something you are.' Biometric factors are based on unique physical or behavioral characteristics of the individual, including fingerprints, retinal patterns, iris scans, facial recognition, voiceprints, and behavioral biometrics. These characteristics are inherent to the person and cannot be easily shared or transferred.
Question 2 Medium
Which of the following authentication methods provides the STRONGEST protection against credential theft through phishing attacks?
Solution
A is correct.

FIDO2 hardware security keys provide the strongest phishing resistance because they use public-key cryptography bound to the legitimate website's origin (domain). When a user authenticates, the security key verifies that the requesting website matches the origin registered during setup. If a phishing site impersonates the legitimate site with a different domain, the key will not respond, making the credential impossible to phish. Additionally, the private key never leaves the hardware device and cannot be extracted.
Question 3 Hard
A financial services company must comply with both NIST CSF and ISO 27001. The CISO notes that NIST CSF is descriptive and flexible while ISO 27001 is prescriptive and certifiable. How should the organization BEST leverage both frameworks in its security program?
Solution
D is correct.

NIST CSF and ISO 27001 are complementary. NIST CSF provides a flexible, risk-based structure organized around five functions that works well for strategic cybersecurity governance. ISO 27001 provides a prescriptive ISMS with specific Annex A controls that can be audited and certified. By using NIST CSF as the overarching risk management framework and mapping its categories and subcategories to specific ISO 27001 controls, the organization achieves both strategic risk management and certifiable compliance.

About FreeFellow

FreeFellow is an AI-native exam prep platform for actuarial (SOA & CAS), CFA, CFP, CPA, CAIA, GARP FRM, IRS Enrolled Agent, IMA CMA, and FINRA / NASAA securities licensing candidates — built around modern AI as a core capability rather than as a bolt-on. Every lesson ships with AI-narrated audio. Every constructed-response item has a copy-to-AI prompt builder so candidates can paste their answer into their own ChatGPT or Claude for self-graded feedback. Fellow members get instant AI grading on essays against the official rubric (currently CFA Level III, expanding to other essay-bearing sections).

The 70% you need to pass — question bank, written solutions, lessons, formula sheet, mixed practice, readiness tracking — is free forever, with no trial period and no credit card. Become a Fellow ($59/quarter or $149/year per track) to unlock mock exams, flashcards with spaced repetition, performance analytics, AI essay grading, and a personalized study plan.