โ† All tools

EPSO/AD/430/26 ยท Cybersecurity ยท AD 8

EPSO cybersecurity field test: 10 questions, exam pace

The only test that ranks candidates in EPSO/AD/430/26 is a 30-question multiple-choice test on the field, 40 minutes, in your second language. Here are 10 questions in the same format and at the same pace (80 seconds each), covering the five duty areas of the notice: risk management, security architecture, operations and incident response, governance, and trust services.

254 posts ยท deadline 13 October 2026, 12:00 Brussels ยท pass mark 15/30 and a ranking

Question 1 of 10Time left1:20

The 80-second clock starts with your first answer.

An essential entity under Directive (EU) 2022/2555 (NIS2) becomes aware of a significant incident on Monday at 09:00. Which sequence of notifications to its CSIRT does the Directive require?

Which language do you sit each test in?

Application formAny of the 24 official EU languages
Reasoning tests (verbal, numerical, abstract)L1Your language 1: any of the 24 official EU languages, minimum level C1
Field test (30 questions, 40 min)L2Your language 2: a different one of the remaining 23, minimum level B2
EUFTE essayL2Your language 2

You declare language 1 and language 2 in the application form, by 13 October. Source: Notice of Competition EPSO/AD/430/26, OJ C/2026/4668, section 4.2.

Download the 10 questions as PDF โ†’

What the field test covers โ€” the full guide โ†’ ยท Competition sheet and deadlines โ†’

The ten questions, with answers and sources

The same ten questions with answers and sources, for reading and for search engines. Real questions from the EU-now bank, written from the official texts. No account.

  1. 1. An essential entity under Directive (EU) 2022/2555 (NIS2) becomes aware of a significant incident on Monday at 09:00. Which sequence of notifications to its CSIRT does the Directive require?

    • A An incident notification within 72 hours and a final report within three months; no early warning is needed.
    • B Early warning within 24 hours, incident notification within 72 hours, final report a month after the notification.
    • C Early warning within 72 hours, incident notification within 24 hours of containment, final report within one month.
    • D A notification to the national data protection authority within 72 hours, as for a personal data breach under the GDPR.
    Correct answer: B

    Article 23 of NIS2 sets a staged scheme: an early warning without undue delay and within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours that updates the early warning and gives an initial assessment, and a final report not later than one month after the incident notification. Source: Directive (EU) 2022/2555, Article 23 and recital 102.

    • A โ€” A 24-hour early warning comes first, and the final report is due one month after the incident notification.
    • B โ€” Correct: 24 hours, 72 hours, one month.
    • C โ€” The deadlines are inverted: the early warning is the 24-hour step and the incident notification the 72-hour one.
    • D โ€” The 72-hour breach notification to a data protection authority is Article 33 GDPR, a different instrument with a different addressee.
  2. 2. Under Regulation (EU, Euratom) 2023/2841 on cybersecurity at the Union institutions, bodies, offices and agencies, how often must each Union entity carry out a cybersecurity maturity assessment after the first one?

    • A At least every two years, covering all elements of its ICT environment.
    • B Every year, as a chapter of the entity's annual activity report.
    • C At least every three years, aligned with the NIS2 supervisory cycle.
    • D Only when CERT-EU requests it after a significant incident.
    Correct answer: A

    Article 7 of Regulation 2023/2841 requires each Union entity to carry out a cybersecurity maturity assessment incorporating all elements of its ICT environment by 8 July 2025 and at least every two years thereafter, where appropriate with a specialised third party. The internal risk-management, governance and control framework itself was due by 8 April 2025 (Article 6). Source: Regulation (EU, Euratom) 2023/2841, Articles 6 and 7.

    • A โ€” Correct: by 8 July 2025 and at least every two years thereafter.
    • B โ€” The Regulation does not tie the assessment to the annual activity report or to a yearly cycle.
    • C โ€” Three years is a NIS2-style figure; the Regulation says two.
    • D โ€” The assessment is a standing obligation of the entity, not something triggered by CERT-EU.
  3. 3. A manufacturer learns that a vulnerability in one of its products with digital elements is being actively exploited. Under Regulation (EU) 2024/2847 (Cyber Resilience Act), what must it do?

    • A Notify the market surveillance authority of its Member State within 30 days, then publish a security advisory with the patch.
    • B Early warning in 24 hours, incident notification in 72 hours and a final report within one month, as for NIS2 incidents.
    • C Report it only to ENISA, within 72 hours, once a patch has been released, and inform users at the next update.
    • D Early warning within 24 hours, vulnerability notification within 72 hours, final report 14 days after a fix is available.
    Correct answer: D

    Article 14 of the Cyber Resilience Act requires manufacturers to notify an actively exploited vulnerability simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. Source: Regulation (EU) 2024/2847, Articles 14 and 16.

    • A โ€” Market surveillance authorities supervise conformity; the reporting duty runs to the coordinator CSIRT and ENISA, with much shorter deadlines.
    • B โ€” That is the NIS2 incident scheme; for an actively exploited vulnerability the CRA sets the final report 14 days after a corrective measure is available.
    • C โ€” The notification is not conditional on a patch, and it goes to the CSIRT and ENISA simultaneously.
    • D โ€” Correct: 24 hours, 72 hours, 14 days, through the single reporting platform.
  4. 4. Which statement correctly describes the European Cybersecurity Alert System created by Regulation (EU) 2025/38 (Cyber Solidarity Act)?

    • A A single EU-level security operations centre, run by ENISA, that replaces the national SOCs of the Member States.
    • B A pool of trusted managed security service providers that Member States can call on after a large-scale cybersecurity incident.
    • C Cross-Border Cyber Hubs, each grouping at least three National Cyber Hubs, that detect threats and share information.
    • D The mechanism through which ENISA, at the Commission's request, reviews significant or large-scale incidents after the fact.
    Correct answer: C

    The Cyber Solidarity Act builds the European Cybersecurity Alert System as several interoperating Cross-Border Cyber Hubs, each grouping together three or more National Cyber Hubs, to strengthen detection and information sharing. The pool of trusted providers is the EU Cybersecurity Reserve, part of the Cybersecurity Emergency Mechanism, and the after-the-fact review is the Cybersecurity Incident Review Mechanism. Source: Regulation (EU) 2025/38, recitals and Chapter II.

    • A โ€” There is no single EU SOC; the system federates national and cross-border hubs and does not replace national capacities.
    • B โ€” That is the EU Cybersecurity Reserve, a separate pillar.
    • C โ€” Correct: cross-border hubs grouping three or more national hubs.
    • D โ€” That is the Cybersecurity Incident Review Mechanism.
  5. 5. In the NIST SP 800-207 zero trust architecture, which components sit between a subject requesting access and the enterprise resource, and what do they do?

    • A A policy decision point that rules on each session and a policy enforcement point that opens, monitors and ends the connection.
    • B A firewall and a VPN concentrator, which grant access to the internal network segment once the device is inside the perimeter.
    • C A SIEM and an XDR agent, which log every session and automatically block it as soon as a correlated alert fires.
    • D A certificate authority and a directory service, which authenticate the user once per day and then trust the device until logout.
    Correct answer: A

    SP 800-207 models zero trust access through a policy decision point and a corresponding policy enforcement point: the PDP evaluates each request against policy and the PEP establishes, monitors and ends the connection. The tenets add that all data sources and computing services are resources and that access is granted per session, so a network location or a daily login does not by itself confer trust. Source: NIST SP 800-207, sections 2 and 3.

    • A โ€” Correct: PDP decides, PEP enforces, per session.
    • B โ€” A perimeter that trusts whatever is inside is exactly what zero trust removes.
    • C โ€” Monitoring tools feed the decision but are not the access control components of the model.
    • D โ€” Zero trust evaluates each session; authenticating once per day contradicts the tenets.
  6. 6. An EU institution wants privileged administrators to authenticate at Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B-4. Which authenticator setup meets AAL3?

    • A A password plus a one-time code sent by SMS to the administrator's registered mobile phone.
    • B A syncable passkey stored in a cloud keychain: phishing-resistant and usable on any of the administrator's devices.
    • C A phishing-resistant, hardware-bound authenticator with a non-exportable key and two distinct factors.
    • D A memorised secret of at least 15 characters, checked against a blocklist and changed every 90 days.
    Correct answer: C

    SP 800-63B-4 requires AAL3 authentication to be based on proof of possession of a key through a public-key protocol, using a phishing-resistant authenticator with a non-exportable key kept in a hardware-protected, isolated environment, and proof of two distinct factors. Because syncable authenticators require an exportable private key, they SHALL NOT be used at AAL3. Source: NIST SP 800-63B-4 (July 2025), section 2.

    • A โ€” An SMS code is neither phishing-resistant nor hardware-bound; it does not reach AAL3.
    • B โ€” Syncable authenticators are explicitly excluded at AAL3 because the key must be exportable to sync.
    • C โ€” Correct: phishing-resistant, non-exportable, hardware-protected, two factors.
    • D โ€” A memorised secret is a single factor, and SP 800-63B-4 forbids requiring periodic password changes.
  7. 7. A security architect must choose post-quantum algorithms for two needs: establishing a shared key for encrypted sessions, and signing software updates. Which NIST standards match each need?

    • A Any of the three interchangeably, since all are lattice-based signature schemes.
    • B FIPS 204 (ML-DSA) for key establishment; FIPS 203 (ML-KEM) for digital signatures.
    • C FIPS 205 (SLH-DSA) for key establishment; FIPS 203 (ML-KEM) for signatures, because hash-based schemes encapsulate keys.
    • D FIPS 203 (ML-KEM) for key establishment; FIPS 204 (ML-DSA) or FIPS 205 (SLH-DSA) for digital signatures.
    Correct answer: D

    FIPS 203 is the Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM), used to establish shared secret keys. FIPS 204 is the Module-Lattice-Based Digital Signature Standard (ML-DSA) and FIPS 205 the Stateless Hash-Based Digital Signature Standard (SLH-DSA), both for signatures. Recommendation (EU) 2024/1101 asks Member States to plan a coordinated transition to such algorithms. Source: NIST FIPS 203, 204 and 205 (August 2024).

    • A โ€” SLH-DSA is hash-based, not lattice-based, and ML-KEM is not a signature scheme.
    • B โ€” Reversed: ML-DSA signs, ML-KEM establishes keys.
    • C โ€” SLH-DSA is a hash-based signature scheme, not a KEM.
    • D โ€” Correct: ML-KEM encapsulates keys; ML-DSA and SLH-DSA sign.
  8. 8. How does NIST SP 800-61 Revision 3 (2025) structure incident response compared with the earlier four-phase life cycle?

    • A It keeps the four-phase life cycle of Revision 2 as the only valid model and adds a fifth phase for AI-related incidents.
    • B It maps incident response onto the six CSF 2.0 functions, making preparation and lessons learned ongoing activities.
    • C It replaces the life cycle with the ISO/IEC 27035 process and hands every response activity to an external CSIRT.
    • D It drops the post-incident activity phase entirely, because lessons learned are now fully covered by SP 800-53 controls.
    Correct answer: B

    Revision 3 presents an incident response life cycle model based on the CSF 2.0 Functions and maps the previous model's phases onto them; preparation and lessons learned become continuous, organisation-wide activities rather than stages of a single incident. Source: NIST SP 800-61r3, sections 1 and 2 (Table 1, Figures 1 and 2).

    • A โ€” The four-phase model of Revision 2 is shown as the previous model; there is no added AI phase.
    • B โ€” Correct: a CSF 2.0-based model with preparation and lessons learned as ongoing activities.
    • C โ€” SP 800-61r3 is NIST guidance, not a hand-over to ISO 27035 or to an external team.
    • D โ€” Post-incident learning is retained and broadened, not removed.
  9. 9. Under Regulation (EU) 2019/881 (Cybersecurity Act), for which assurance level may a manufacturer rely on a conformity self-assessment instead of third-party certification?

    • A Any level, provided ENISA is notified.
    • B Assurance levels 'basic' and 'substantial'.
    • C Assurance level 'basic' only.
    • D None: European cybersecurity certification is always issued by a conformity assessment body.
    Correct answer: C

    The Cybersecurity Act defines three assurance levels, 'basic', 'substantial' and 'high', and allows conformity self-assessment only where the ICT product, service or process corresponds to assurance level 'basic'; the higher levels require evaluation by a conformity assessment body. The first scheme adopted under this framework is EUCC (Implementing Regulation (EU) 2024/482). Source: Regulation (EU) 2019/881, recitals 79โ€“80 and Article 53.

    • A โ€” ENISA prepares schemes; it neither certifies nor receives self-assessment notifications in this sense.
    • B โ€” 'Substantial' requires third-party evaluation.
    • C โ€” Correct: self-assessment is permitted for 'basic' only.
    • D โ€” Self-assessment exists, but only for the lowest level.
  10. 10. Under Regulation (EU) 2022/2554 (DORA), how often must financial entities identified by their competent authority carry out threat-led penetration testing (TLPT)?

    • A At least every 3 years, or more often if the competent authority so requests.
    • B Every year, as part of the annual review of the ICT risk-management framework.
    • C Only after a major ICT-related incident has been reported to the competent authority.
    • D Every 5 years, in line with the audit cycle for essential entities under NIS2.
    Correct answer: A

    Article 26 of DORA requires financial entities identified under its paragraph 8 (other than microenterprises) to carry out advanced testing by means of TLPT at least every 3 years; the competent authority may request more frequent testing depending on the entity's risk profile and operational circumstances. Source: Regulation (EU) 2022/2554, Article 26.

    • A โ€” Correct: at least every 3 years, more often on request.
    • B โ€” Yearly tests belong to the general testing programme of Article 24; TLPT has its own three-year rhythm.
    • C โ€” TLPT is a scheduled requirement, not an incident-triggered one.
    • D โ€” Five years and the NIS2 cycle are not in DORA.

Every explanation cites the official text it is drawn from: the Notice of Competition C/2026/4668 and the regulations, NIST and ENISA publications listed on the field guide.