Skip to content

EDU-102 Fundamentals of Cybersecurity (EDU-102) Practice Questions

Prepare for EDU-102 with more than an answer.

150 questions in the full set12 sample questionsUpdated Aug 8, 2026
Exam fee
$300 USD
Time limit
40 minutes
Passing score
70%
Level
Foundational
Valid for
2 years
Domains covered on the exam 9
  1. Describe cybersecurity and attack surface11%
  2. List the types of cybersecurity11%
  3. Discuss the importance of cybersecurity for businesses11%
  4. Describe cybersecurity framework and compliance11%
  5. Explain cyber threats, cyberattacks, and cybers attackers11%
  6. Discuss various types of cyberattacks11%
  7. Define cyber safety and its measures11%
  8. Discuss perimeter based and zero trust security models11%
  9. Explain Zscaler Zero Trust Exchange12%
  1. 1

    A well-known retail brand suffered a major data breach resulting in millions of leaked customer credit card numbers. Following the breach, the company experienced a 30% drop in stock price and lost thousands of loyal customers to competitors. Which business impact of poor cybersecurity does this primarily illustrate?

    Show answer details

    Correct answer: B

    The scenario highlights loss of customer trust (reputation) and a drop in stock value (financial damage), which are direct business consequences of a severe data breach.

  2. 2

    A healthcare provider is upgrading its legacy database systems. The board of directors approves a significant budget specifically to ensure patient records are encrypted and access is strictly audited.

    pie title Drivers for Security Investment "Regulatory Requirements" : 45 "Risk Mitigation" : 30 "Business Enablement" : 25

    Given the industry context, which of the following is the most likely primary driver for this specific cybersecurity investment?

    Show answer details

    Correct answer: B

    For healthcare organizations, regulatory compliance (like HIPAA in the US) is a massive driver for cybersecurity investments. Failure to secure patient records can lead to severe legal penalties and fines, making regulatory obligations a primary business driver.

  3. 3

    The CISO of a manufacturing firm is presenting a budget request for a new automated backup and disaster recovery system. To justify the cost to the board, the CISO explains that a ransomware attack would halt assembly lines, costing the company $100,000 per hour in lost revenue. Which fundamental business concept of cybersecurity is the CISO utilizing?

    Show answer details

    Correct answer: B

    The CISO is translating technical threats (ransomware) into quantifiable business impacts ($100k/hour downtime). This demonstrates that cybersecurity is critical for business continuity, allowing executives to weigh the cost of the security control against the potential financial loss.

  4. 4

    True or False: Modern businesses should view cybersecurity primarily as an IT-centric cost center rather than a strategic business enabler, since security controls generally slow down employee productivity and innovation.

    Show answer details

    Correct answer: B

    False. Modern cybersecurity is increasingly viewed as a strategic business enabler. Effective security builds customer trust, protects intellectual property, and enables safe digital transformation (like adopting cloud services or remote work), rather than merely being a technical cost center.

  5. 5

    A financial services organization is migrating its core banking application to the cloud. The Chief Information Security Officer (CISO) emphasizes that the migration must not compromise the 'CIA Triad.' In this context, which of the following best describes the 'Integrity' component of the CIA Triad?

    Show answer details

    Correct answer: B

    In the CIA Triad (Confidentiality, Integrity, Availability), Integrity refers to maintaining the accuracy, consistency, and trustworthiness of data over its entire lifecycle. It ensures that data cannot be altered in transit or at rest by unauthorized parties.

  6. 6

    Nimbus Logistics recently transitioned to a fully remote workforce, allowing employees to access corporate resources from personal devices and public Wi-Fi networks. Which of the following factors contribute to the expansion of the company's attack surface in this scenario? (Select THREE)

    Show answer details

    Correct answer: A, C, E

    Unmanaged personal devices introduce new potential entry points for attackers, increasing the attack surface.

    Unsecured public networks expose data in transit to interception, adding to the attack surface.

    Exposing services to the internet for VPN access creates discoverable nodes that attackers can target, expanding the attack surface.

Create an account to continue.