
Dell NIST Cybersecurity Framework v2.0
Domain 9Objective 2
Choose Appropriate Tiers for Risk Governance and Management. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 3)
Part of the Applying NIST CSF Tiers domain, which accounts for 5% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
20questions here
4free pages
4concepts
5%of the exam
Questions 11–15
- 11
An organization with a high risk appetite and a rapidly evolving threat landscape is most likely to select which NIST CSF tier?
Select an answer first - 12
A manufacturing company currently operates at Tier 2 (Risk Informed). They have formal risk assessment processes, but these are applied inconsistently across different business units. The company wants to progress to Tier 3 (Repeatable). What is the most critical step to achieve this progression?
Select an answer first - 13
A non-profit organization handles sensitive donor information but has a limited budget and a moderate risk appetite. They have some informal security practices but no formal risk management process. They are considering adopting the NIST CSF. Which tier is the most realistic starting point for their risk governance?
Select an answer first - 14
A financial services company is at Tier 3 (Repeatable) and wants to progress to Tier 4 (Adaptive). They have consistent processes and organization-wide integration, but their risk management is largely reactive to incidents. Which capability is most critical to develop to achieve Tier 4?
Select an answer first - 15
A government agency is required by law to protect citizen data and faces persistent cyber threats from nation-state actors. It has a low risk appetite and must demonstrate due diligence to auditors. The agency has formal risk management processes but they are not yet consistently applied across all departments. Which tier should the agency target to meet its obligations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.