Skip to content

PECB-NIS2-LI PECB Certified NIS 2 Directive Lead Implementer Practice Questions

Prepare for PECB-NIS2-LI with more than an answer.

245 questions in the full set20 sample questionsUpdated Jan 27, 2026
Exam fee
$1000 USD
Level
Lead Implementer
Valid for
3 years
Domains covered on the exam 6
  1. Fundamental concepts and definitions of NIS 2 Directive12.5%
  2. Planning of NIS 2 Directive requirements implementation25%
  3. Cybersecurity roles and responsibilities and risk management18.75%
  4. Cybersecurity controls, incident management, and crisis management18.75%
  5. Communication and awareness12.5%
  6. Testing and monitoring of a cybersecurity program12.5%
  1. 1

    A lead implementer is helping a medium-sized cloud computing provider define its asset management process for NIS 2. According to best practices like ISO/IEC 27001, which sequence of activities is correct for establishing asset management?

    Show answer details

    Correct answer: C

    The logical flow of asset management begins with identifying what you have (Create Inventory). Once assets are identified, someone must be responsible for them (Assign Ownership). The next step is to determine the value and sensitivity of the assets (Classify Information). Based on the classification, you can then establish appropriate protection measures (Define Handling Rules).

  2. 2

    A financial services company, deemed an 'essential entity', is conducting an internal audit of its NIS 2 compliance program. The audit finds that while a comprehensive risk assessment was performed, the risk treatment plan has not been formally approved by the management body. What is the direct consequence of this finding?

    Show answer details

    Correct answer: B

    Article 20 of the NIS 2 Directive explicitly states that management bodies must 'approve the cybersecurity risk-management measures taken by those entities'. The risk treatment plan is a fundamental component of these measures. Failure to secure formal approval represents a direct failure in governance and oversight, making the management body directly accountable for this non-compliance.

  3. 3

    When planning a NIS 2 implementation, a lead implementer must gather information about the organization's context. Which of the following information gathering techniques would be most effective for understanding the informal communication channels and undocumented processes that could impact cybersecurity?

    Show answer details

    Correct answer: C

    While reviewing documentation and using questionnaires are valuable for understanding formal structures, interviews and workshops are superior for uncovering the 'way things are actually done.' They allow for follow-up questions, discussion, and observation of group dynamics, which are essential for identifying undocumented processes and informal communication paths that represent potential cybersecurity risks.

  4. 4

    Case Study: ConnectSphere Telecom

    Company Background: ConnectSphere Telecom is a provider of public electronic communications networks in a Member State and is an 'essential entity'. They are in the process of implementing their NIS 2 compliance program. A key part of their service delivery relies on several key suppliers, including a data center provider, a network equipment manufacturer, and a provider of billing software.

    Problem: The lead implementer is tasked with addressing the supply chain security requirements of Article 21. The initial review shows that supplier contracts have generic security clauses but lack specific details. The procurement team has historically prioritized cost and features over the cybersecurity practices of suppliers. There is no formal process for assessing the cybersecurity posture of a supplier before or during a contract.

    Question: To build a compliant and effective supply chain risk management program, which of the following actions should the lead implementer prioritize? (Select TWO)

    Show answer details

    Correct answer: B, D

    NIS 2 requires entities to manage risks in their supply chain. The two most fundamental and proactive steps are to: 1) Establish a process to assess suppliers' security based on risk (criticality), and 2) Embed security requirements and rights into the legal agreements (contracts). These actions form the foundation of the program. Replacing all non-certified suppliers is often impractical and not explicitly required, while insurance is a risk transfer mechanism, not a risk management control.

  5. 5

    The NIS 2 incident reporting process involves multiple stages. What is the primary purpose of the 'intermediate report' that may be requested by the CSIRT or competent authority?

    Show answer details

    Correct answer: C

    The multi-stage reporting process (early warning, incident notification, intermediate report, final report) is designed to keep authorities informed during a live incident. The intermediate report, as described in Article 23, serves to provide relevant status updates upon request, bridging the gap between the initial notification and the final report, especially for long-running incidents.

  6. 6

    A multinational logistics company, classified as an 'essential entity' in several EU Member States, uses a centralized security operations center (SOC) in a non-EU country. To comply with NIS 2, the company must ensure its incident reporting obligations are met. Which statement accurately describes the jurisdictional responsibility for reporting a significant incident that affects services in Germany and Poland?

    Show answer details

    Correct answer: B

    According to Article 23 of the NIS 2 Directive, if an incident affects the provision of services in more than one Member State, the entity must notify the competent authorities of each of those Member States. The principle of 'main establishment' applies for general jurisdiction, but incident reporting has a specific requirement to inform all affected states to ensure a coordinated response.

  7. 7

    A lead implementer is drafting a cybersecurity policy for a newly classified 'important entity' in the food production sector. The policy must align with the risk management measures mandated by Article 21 of the NIS 2 Directive. Which of the following areas must be included in the policy as a baseline requirement? (Select TWO)

    Show answer details

    Correct answer: A, D

  8. 8

    True or False: Under the NIS 2 Directive, the management body of an essential entity can delegate the legal liability for non-compliance with cybersecurity risk management obligations to a third-party managed security service provider (MSSP) through a contractual agreement.

    Show answer details

    Correct answer: B

    False. Article 20 of the NIS 2 Directive places direct responsibility on the management bodies of essential and important entities. They must approve and oversee the implementation of cybersecurity risk-management measures. This liability cannot be delegated to a third party. While an MSSP can be used for implementation and operations, the ultimate legal accountability remains with the entity's management body.

  9. 9

    Case Study: AquaPure Water Services

    Company Background: AquaPure Water Services is a public utility responsible for drinking water supply and wastewater management for a region of over one million people in an EU Member State. They are classified as an 'essential entity' under NIS 2. Their operations rely heavily on an Industrial Control System (ICS) and SCADA network to manage water treatment plants, pumping stations, and distribution networks. This OT network has been historically air-gapped but now has limited, firewalled connections to the corporate IT network for reporting and maintenance purposes.

    Current Situation: During a preliminary NIS 2 gap analysis, the newly appointed lead implementer discovers that AquaPure has no formal business continuity or crisis management plans specifically for cyber incidents affecting the OT environment. The existing disaster recovery plan only covers physical failures like pump malfunctions or power outages. Furthermore, the engineering team that manages the OT network has a separate command structure from the IT department, and there is no integrated incident response plan.

    Requirements: The CEO has tasked the lead implementer with developing a plan to meet the business continuity and crisis management requirements of NIS 2. The primary concern is ensuring the continuity of safe drinking water supply in the event of a significant cyberattack, such as ransomware encrypting SCADA servers.

    Question: As the lead implementer, what is the most critical first step AquaPure should take to develop a NIS 2-compliant cyber crisis management and business continuity capability?

    Show answer details

    Correct answer: B

    The most critical first step in developing any business continuity capability is to understand the impact of a disruption. A Business Impact Analysis (BIA) will identify critical processes (like water purification and distribution), the impact of their failure over time, and inform the setting of RTOs and RPOs. This analysis is the foundation upon which all subsequent crisis management, incident response, and business continuity plans will be built, ensuring that efforts are prioritized correctly. The other options are either subsequent steps (C, D) or a specific technical control that doesn't address the strategic planning gap (A).

  10. 10

    A lead implementer is creating a project plan for achieving NIS 2 compliance. The organization is a large digital service provider. The plan needs to account for all key phases of the implementation. Which of the following represents the most logical sequence of phases for the implementation project?

    graph TD A[Initiation & Scoping] --> B{...} B --> C[Control Implementation & Operations] C --> D[Monitoring & Continual Improvement]

    Show answer details

    Correct answer: B

    A standard implementation lifecycle follows a logical progression. After initiating the project and defining its scope, the next crucial phase is to understand the current state versus the desired state (Gap Analysis) and to identify and evaluate the specific risks the organization faces (Risk Assessment). The outputs of this phase directly inform which controls need to be implemented in the subsequent phase.

Create an account to continue.