
Dell NIST Cybersecurity Framework v2.0
Domain 2Objective 5
Define Clear Roles and Responsibilities for Cybersecurity Personnel. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 3)
Part of the NIST Framework: GOVERN Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
23questions here
5free pages
5concepts
18%of the exam
Questions 11–15
- 11
A bank's security charter assigns the 'Fraud Analyst' role the task of reviewing and approving all wire transfers over $10,000. The charter is stored in a secure document management system that only the compliance team can access. The fraud analysts have never seen the charter. What is the most likely consequence of this situation?
Select an answer first - 12
A startup is defining its first cybersecurity roles. The CEO wants a single point of contact for all security matters and a clear chain of command. The company has only five employees, and the CEO is not technical. Which role definition best meets the CEO's needs?
Select an answer first - 13
A manufacturing company's cybersecurity charter states that the plant manager is responsible for approving all OT network changes. The company recently hired a dedicated OT security engineer and created a new security operations center (SOC) that monitors the OT network. The charter has not been updated in two years. Which action best reflects the Review and Update concept?
Select an answer first - 14
A healthcare provider has a policy that grants the 'Privacy Officer' the authority to approve all access to patient records. The Privacy Officer is a part-time contractor who works only two days a week. The clinical staff need access to patient records 24/7 for emergency care. The current process causes dangerous delays. The CIO wants to maintain compliance with privacy regulations while ensuring timely access. What is the most balanced solution?
Select an answer first - 15
A mid-sized e-commerce company is defining roles for its new security program. The CISO wants to ensure that the person who approves access to the production database is not the same person who administers the database. This is a classic separation-of-duties requirement. Which role definition best satisfies this control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.