Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 9Objective 2

Choose Appropriate Tiers for Risk Governance and Management. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 2)

Part of the Applying NIST CSF Tiers domain, which accounts for 5% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

20questions here
4free pages
4concepts
5%of the exam

Questions 6–10

  1. 6expert · hard

    A global technology company has achieved Tier 4 (Adaptive) in most business units. However, a newly acquired subsidiary operates at Tier 1 (Partial). The company's risk governance requires a single, consistent tier across the entire organization. What is the most appropriate approach?

    Select an answer first
  2. 7application · medium

    A technology company has a mature security program with consistent, documented processes. They regularly share threat intelligence with industry peers and adjust their controls in near real-time based on emerging threats. However, they have not yet integrated cyber risk metrics into their enterprise risk management dashboard. Which NIST CSF tier best describes this organization?

    Select an answer first
  3. 8expert · hard

    A mid-sized logistics company operates at Tier 2 (Risk Informed). It has formal risk processes, but they are siloed within the IT department and not integrated with enterprise risk management. The company's leadership wants to progress to Tier 3 (Repeatable) without overburdening the small risk team. Which approach best balances the need for progression with resource constraints?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of progressing from a lower NIST CSF tier to a higher one?

    Select an answer first
  5. 10application · medium

    A university is at Tier 2 (Risk Informed) and wants to progress to Tier 3 (Repeatable). They have formal risk processes but they are not consistently applied across departments. The university has a decentralized structure, making it challenging to enforce uniform practices. Which approach is most effective for achieving Tier 3?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.