A multinational logistics company, classified as an 'essential entity' in several EU Member States, uses a centralized security operations center (SOC) in a non-EU country. To comply with NIS 2, the company must ensure its incident reporting obligations are met. Which statement accurately describes the jurisdictional responsibility for reporting a significant incident that affects services in Germany and Poland?
Answer and explanation
Correct answer: B
According to Article 23 of the NIS 2 Directive, if an incident affects the provision of services in more than one Member State, the entity must notify the competent authorities of each of those Member States. The principle of 'main establishment' applies for general jurisdiction, but incident reporting has a specific requirement to inform all affected states to ensure a coordinated response.
Question 2
Multiple answers
A lead implementer is drafting a cybersecurity policy for a newly classified 'important entity' in the food production sector. The policy must align with the risk management measures mandated by Article 21 of the NIS 2 Directive. Which of the following areas must be included in the policy as a baseline requirement? (Select TWO)
Answer and explanation
Correct answers: A, D
Question 3
True or False: Under the NIS 2 Directive, the management body of an essential entity can delegate the legal liability for non-compliance with cybersecurity risk management obligations to a third-party managed security service provider (MSSP) through a contractual agreement.
Answer and explanation
Correct answer: B
False. Article 20 of the NIS 2 Directive places direct responsibility on the management bodies of essential and important entities. They must approve and oversee the implementation of cybersecurity risk-management measures. This liability cannot be delegated to a third party. While an MSSP can be used for implementation and operations, the ultimate legal accountability remains with the entity's management body.
Question 4
Case Study: AquaPure Water Services
Company Background: AquaPure Water Services is a public utility responsible for drinking water supply and wastewater management for a region of over one million people in an EU Member State. They are classified as an 'essential entity' under NIS 2. Their operations rely heavily on an Industrial Control System (ICS) and SCADA network to manage water treatment plants, pumping stations, and distribution networks. This OT network has been historically air-gapped but now has limited, firewalled connections to the corporate IT network for reporting and maintenance purposes.
Current Situation: During a preliminary NIS 2 gap analysis, the newly appointed lead implementer discovers that AquaPure has no formal business continuity or crisis management plans specifically for cyber incidents affecting the OT environment. The existing disaster recovery plan only covers physical failures like pump malfunctions or power outages. Furthermore, the engineering team that manages the OT network has a separate command structure from the IT department, and there is no integrated incident response plan.
Requirements: The CEO has tasked the lead implementer with developing a plan to meet the business continuity and crisis management requirements of NIS 2. The primary concern is ensuring the continuity of safe drinking water supply in the event of a significant cyberattack, such as ransomware encrypting SCADA servers.
Question: As the lead implementer, what is the most critical first step AquaPure should take to develop a NIS 2-compliant cyber crisis management and business continuity capability?
Answer and explanation
Correct answer: B
The most critical first step in developing any business continuity capability is to understand the impact of a disruption. A Business Impact Analysis (BIA) will identify critical processes (like water purification and distribution), the impact of their failure over time, and inform the setting of RTOs and RPOs. This analysis is the foundation upon which all subsequent crisis management, incident response, and business continuity plans will be built, ensuring that efforts are prioritized correctly. The other options are either subsequent steps (C, D) or a specific technical control that doesn't address the strategic planning gap (A).
Question 5
A lead implementer is creating a project plan for achieving NIS 2 compliance. The organization is a large digital service provider. The plan needs to account for all key phases of the implementation. Which of the following represents the most logical sequence of phases for the implementation project?
graph TD
A[Initiation & Scoping] --> B{...}
B --> C[Control Implementation & Operations]
C --> D[Monitoring & Continual Improvement]
Answer and explanation
Correct answer: B
A standard implementation lifecycle follows a logical progression. After initiating the project and defining its scope, the next crucial phase is to understand the current state versus the desired state (Gap Analysis) and to identify and evaluate the specific risks the organization faces (Risk Assessment). The outputs of this phase directly inform which controls need to be implemented in the subsequent phase.
Question 6
During a review of a draft incident response plan for an 'essential entity', the lead implementer notes that the plan triggers reporting to the national CSIRT only for incidents that have resulted in confirmed data exfiltration. Why is this plan non-compliant with the NIS 2 Directive's definition of a 'significant incident'?
Answer and explanation
Correct answer: B
Article 23(3) defines a 'significant incident' as one that either causes or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, OR affects or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. By focusing only on data exfiltration, the plan ignores the critical criterion of operational disruption, which is a key trigger for reporting under NIS 2.
Question 7
An organization is setting up a program to monitor its NIS 2 compliance. The management body requires a dashboard with Key Performance Indicators (KPIs). Which of the following would be the LEAST effective KPI for demonstrating the effectiveness of the cybersecurity risk management program to the management body?
Answer and explanation
Correct answer: B
The number of trouble tickets is an operational metric that can be influenced by many factors (e.g., new system rollouts, user error, minor issues). It does not directly measure the effectiveness of risk management in preventing significant incidents. A high number could even indicate better user reporting. The other options are much better indicators of risk reduction, control effectiveness, and response capability.
Question 8
A public administration body in a Member State is considered an 'essential entity'. It is undergoing a NIS 2 implementation and needs to establish a cybersecurity training program for its management body. What is the primary objective of this training as mandated by the NIS 2 Directive?
Answer and explanation
Correct answer: C
Article 20 of the NIS 2 Directive requires that members of the management bodies follow training. The goal is not for them to become technical experts, but to equip them with the necessary knowledge to fulfill their oversight responsibilities. This includes being able to identify cybersecurity risks and assess the adequacy of the organization's risk-management practices and their implications for the services provided.
Question 9
A lead implementer is conducting a risk assessment for a digital marketplace platform, which is an 'important entity'. The assessment identifies a critical risk related to a third-party payment gateway provider. The provider has suffered breaches in the past. What is the most appropriate risk treatment strategy in alignment with NIS 2's focus on supply chain security?
Answer and explanation
Correct answer: D
NIS 2 places strong emphasis on managing supply chain security (Article 21). While risk acceptance, transference (insurance), and avoidance are valid strategies, they are not the primary approach for a critical, ongoing third-party dependency. Mitigation through active security management—including contractual obligations, due diligence (assessments), and joint planning—is the most comprehensive and compliant strategy to manage the risk associated with a critical supplier.
Question 10
Multiple answers
When planning the implementation of NIS 2 requirements for a cross-border healthcare provider, the lead implementer must define the scope of the compliance program. Which elements are essential to define in this scoping phase? (Select THREE)