EMC NIST Cybersecurity Framework 2023 Sample Questions:
1. The warranty on your organization's air conditioning system has expired. No alert was sent to anyone within the organization. During an extended number of days of record heat, the air conditioning units fail.
However, maintenance personnel will not work on non-warrantied systems.
Failing to catalog warranty information about the air conditioning units is a failure in which function?
A) Protect
B) Detect
C) Recover
D) Identify
2. A CISO is looking for a solution to lower costs, enhance overall efficiency, and improve the reliability of monitoring security related information.
Which ISCM feature is recommended?
A) Collection
B) Reporting
C) Provisioning
D) Automation
3. To generate an accurate risk assessment, organizations need to gather information in what areas?
A) Assets, Threats, Vulnerabilities, and Impact
B) Assets, Vulnerabilities, Security, and Response
C) Inventory, Security, Response, and Impact
D) Inventory, Threats, Security, and Impact
4. A bank has been alerted to a breach of its reconciliation systems. The notification came from the cybercriminals claiming responsibility in an email to the CEO. The CEO has alerted the company CSIRT.
What does the Communication Plan for the IRP specifically guide against?
A) Initiating kill chain
B) Rushed disclosure
C) Transfer of chain of custody
D) Accelerated turn over
5. What entity offers a framework that is ideally suited to handle an organization's operational challenges?
A) NIST
B) ISO
C) COSO
D) COBIT
Solutions:
Question # 1 Answer: D | Question # 2 Answer: D | Question # 3 Answer: A | Question # 4 Answer: B | Question # 5 Answer: B |