Hands-On Practice

Hands-On Labs

Ten scenario-based exercises that put the manager mindset to work — read the situation, make the management decision, produce the deliverable, then reveal the manager’s debrief to check your reasoning. Weighted to the exam blueprint and tagged by domain for targeted practice or classroom assignment.

Practice

Work the labs

How to use: Each lab is self-contained — a realistic scenario, a defined management decision, and a deliverable to produce. Attempt it first, then open “Reveal the manager’s debrief” for the model answer and the exam-relevant reasoning. Faculty can assign a lab as graded work or self-study. Filter by domain below.

Lab 1

Repositioning Security as a Business Enabler

D1 · GovernanceFoundational⏱ ~25 min
Scenario

A new CISO inherits a security function that operates as a technical gatekeeper: it blocks projects, has no board visibility, and its “strategy” is a list of tools. The business sees security as a cost center that slows delivery.

Your decision

As the security manager, outline how to reposition the program to be business-aligned and properly governed.

Deliverable

A short plan: the governance changes, how the strategy derives from business objectives, and two or three metrics that demonstrate value.

Reveal the manager’s debrief

Security exists to enable the business. Derive the strategy from business objectives, not tools: understand objectives → gap analysis → a risk-based roadmap. Establish governance: an IT/security steering committee, a CISO reporting line with enough independence to report risk candidly, and a risk appetite set by the business.

Demonstrate value with outcome metrics — risk reduced, KRIs trending, alignment to objectives — not activity counts like “emails blocked.” The manager aligns, advises, and oversees; the business owns and accepts risk.

Lab 2

Choosing Board-Level Governance Metrics

D1 · GovernanceIntermediate⏱ ~20 min
Scenario

The board wants a one-page security dashboard. The team proposes: (a) number of emails blocked; (b) % of staff who completed awareness training; (c) number of overdue high-risk findings trending upward; (d) mean time to deploy critical patches; (e) reduction in phishing susceptibility linked to breach likelihood.

Your decision

Classify each as a KGI, KPI, or KRI, and pick the two most useful for the board.

Deliverable

The classifications plus your top two with rationale.

Reveal the manager’s debrief

KGI = whether a goal was achieved; KPI = process performance; KRI = a forward-looking signal that risk is rising. (a) an activity metric (weak); (b) KPI; (c) KRI — overdue high-risk findings trending up; (d) KPI; (e) the strongest board metric — it ties a control to business risk (breach likelihood).

Best for the board: (e) and (c). Leadership needs risk and value in business terms, not raw activity counts like emails blocked or firewall rules configured.

Lab 3

Quantitative Risk Analysis (SLE / ARO / ALE)

D2 · Risk ManagementIntermediate⏱ ~25 min
Scenario

A customer database is valued at $2,000,000. A ransomware event would impair an estimated 40% of its value (exposure factor 0.4) and is expected roughly once every four years. A proposed control costs $90,000/year and would halve the event frequency.

Your decision

Compute SLE, ARO, and ALE before and after the control, and make a treat-or-accept recommendation.

Deliverable

The numbers plus your recommendation with justification.

Reveal the manager’s debrief

SLE = AV × EF = $2,000,000 × 0.4 = $800,000. ARO = 1/4 = 0.25. ALE = SLE × ARO = $200,000/yr. With the control, ARO = 0.125 → ALE = $100,000/yr.

The control reduces ALE by ~$100,000/yr for $90,000/yr — net positive, and a control shouldn’t cost more than the risk it reduces, so it is justifiable. Recommend implementing and monitoring; the business risk owner makes the final treat/accept decision.

Lab 4

Risk Treatment & Formal Acceptance

D2 · Risk ManagementIntermediate⏱ ~20 min
Scenario

After mitigation, a residual risk on a legacy system still exceeds the organization’s stated risk appetite. Separately, a business unit wants a temporary exception to a security policy to hit a launch deadline.

Your decision

Decide the correct course for both the residual risk and the exception request — and who must sign off.

Deliverable

Your recommended actions and the required approver for each.

Reveal the manager’s debrief

Residual risk above appetite: recommend further treatment and escalate to the business risk owner for the decision. The manager does not accept risk on the organization’s behalf, delete it from the register, or re-classify the asset to make the number look better.

Policy exception: document the residual risk and obtain a formal, time-bound acceptance from the risk owner — never an informal “yes,” and never delete the requirement. Acceptance is legitimate only when it is within appetite (or explicitly escalated), documented, and made by the right authority.

Lab 5

Risk-Based Control Selection

D3 · Security ProgramIntermediate⏱ ~25 min
Scenario

Leadership asks you to “add the latest AI-powered security tool everyone’s buying.” Budget is tight. Meanwhile, MFA cannot be deployed on a critical legacy system.

Your decision

Describe how you decide whether to buy the tool, and what to do about the legacy system.

Deliverable

A decision approach plus the legacy-system recommendation.

Reveal the manager’s debrief

Control selection is risk-based: start from the control objective (the risk to reduce), then choose a proportionate control — don’t buy novelty or copy a competitor. If an existing layer already meets the objective, the spend is hard to justify (cost shouldn’t exceed the risk reduced).

For the legacy system where MFA isn’t feasible, apply a compensating control (enhanced monitoring, tighter network restrictions) that achieves comparable risk reduction, documented and approved. Reinforce with framework baselines and defense in depth.

Lab 6

Third-Party Risk & Due Diligence

D3 · Security ProgramIntermediate⏱ ~30 min
Scenario

A business unit wants to onboard a critical SaaS vendor next week. The vendor’s SOC 2 Type II lists a CUEC (“the customer reviews privileged access quarterly”), carves out its subservice cloud provider, and the draft contract has no right-to-audit clause.

Your decision

State what must happen before the organization engages the vendor.

Deliverable

A pre-engagement checklist.

Reveal the manager’s debrief
  1. Perform security due diligence before engaging — review the SOC 2 (design and operating effectiveness over the period) and note reliance limitations.
  2. The CUEC is your responsibility: ensure the organization will actually perform the quarterly privileged-access review.
  3. The carved-out subservice provider needs separate assurance.
  4. Negotiate a right-to-audit clause (and continuity/RTO commitments) into the contract.

Signing quickly to hit a deadline, or assuming a well-known vendor is secure, is unverified trust — and accountability for the data always stays with your organization.

Lab 7

Awareness-Program Effectiveness

D3 · Security ProgramFoundational⏱ ~20 min
Scenario

Phishing-simulation click rates have risen for three straight quarters despite annual training. A director proposes disciplining repeat clickers; IT proposes blocking all external email.

Your decision

Decide the best response and explain why the alternatives are wrong.

Deliverable

Your recommendation with reasoning.

Reveal the manager’s debrief

A rising click rate is a measured decline in program effectiveness — review and strengthen the awareness program’s content, frequency, and reinforcement (role-based, more frequent, positively reinforced).

Disciplining employees is punitive and ignores effectiveness; blocking all external email is impractical and doesn’t address the human layer; discontinuing simulations removes the measurement, not the problem. The goal is a security culture, driven from the top.

Lab 8

Directing Incident Response

D4 · Incident ManagementIntermediate⏱ ~30 min
Scenario

A malware outbreak is spreading. Under pressure, responders want to power off and re-image the compromised server immediately. The CEO is asking you for a decision.

Your decision

Describe how you, as the security manager, direct the response — and the correct technical sequence.

Deliverable

Your coordination actions plus the lifecycle sequence.

Reveal the manager’s debrief

The manager coordinates and directs the response while specialists execute — you don’t perform containment personally, and you don’t wait for it to resolve itself. Direct the team to contain first (isolate affected systems), preserve volatile evidence before powering anything off (memory and network state, chain of custody), then eradicate, then recover.

Powering off destroys forensic data and may breach legal-hold duties. Coordinate executive and stakeholder communication, and ensure the regulatory-notification branch is evaluated. Severity is a business-impact judgment, which is why the manager owns the criteria.

Lab 9

BIA → Recovery-Objective Gap

D4 · Incident ManagementAdvanced⏱ ~30 min
Scenario

The BIA sets the order system at RTO = 4 hours, RPO = 1 hour. The current DR is a warm site fed by nightly backups (recovers in 10–12 hours; data up to ~24h old). Finance proposes “just change the RTO to 12 hours so we pass.”

Your decision

Respond to the capability gap and to the “change the RTO” proposal.

Deliverable

The gaps plus your recommendation and how you handle the proposal.

Reveal the manager’s debrief

RTO gap (10–12h vs. 4h) and RPO gap (~24h vs. 1h) are real capability shortfalls. The BIA sets the objectives from business impact; the DRP must be built and funded to meet them — you don’t raise the BIA’s RTO to match what the DRP can already do (that inverts the relationship and manufactures a “pass”).

Recommend a higher-tier strategy (a hot site / near-continuous replication) for this critical process, or a documented, senior-level business decision to accept a lower objective with the residual risk owned. And remember: RTO must be shorter than the MTD.

Lab 10

Coordinating a Breach Notification

D4 · Incident ManagementIntermediate⏱ ~25 min
Scenario

You confirm attackers exfiltrated a database holding EU residents’ personal data and cardholder data. Legal is on holiday, and a manager suggests waiting until the forensic investigation is complete before telling anyone.

Your decision

Determine the notification obligations and your coordination steps.

Deliverable

The timeline/obligations and who you engage.

Reveal the manager’s debrief

Under the GDPR, notify the supervisory authority without undue delay and, where feasible, within 72 hours of the organization becoming aware — the clock starts at organizational awareness, not when Legal or the DPO returns, and you cannot wait for the investigation to finish. The cardholder data separately triggers PCI DSS and payment-brand reporting.

Coordinate: engage legal / DPO / communications per the plan, define who declares a breach and who notifies each party, and disclose through proper channels within the required timeframe. Concealing a reportable breach to protect the organization’s image is not acceptable.