Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 3Objective 5

Describe Risk Assessment. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 1)

Part of the NIST Framework: IDENTITY Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

22questions here
5free pages
5concepts
18%of the exam

Questions 1–5

  1. 1application · medium

    A logistics company is starting a risk assessment for its new fleet management system. The team has identified potential threats such as GPS spoofing, unauthorized access to the tracking platform, and physical tampering with vehicle sensors. They are now listing the vulnerabilities in the system that could be exploited by these threats. Which step of the risk assessment process are they performing?

    Select an answer first
  2. 2application · medium

    A manufacturing company has completed a risk assessment and identified three risks: (1) a ransomware attack on the corporate network, (2) a physical theft of laptops from a warehouse, and (3) a phishing campaign targeting executives. The risk team must decide which risk to address first. They have rated the likelihood and impact of each risk on a scale of 1 to 5. Risk 1 has likelihood 4 and impact 5, Risk 2 has likelihood 2 and impact 3, and Risk 3 has likelihood 5 and impact 4. According to a simple likelihood-impact matrix, which risk should be prioritized first?

    Select an answer first
  3. 3expert · hard

    A manufacturing company is adopting the NIST Cybersecurity Framework. They have conducted a risk assessment and identified that a cyberattack on their industrial control systems (ICS) could cause significant production downtime. The company's management is considering whether to invest in additional security controls or accept the risk. What is the role of the risk assessment in this decision?

    Select an answer first
  4. 4application · medium

    A university's IT department has identified several risks: a distributed denial-of-service (DDoS) attack on the public website, a ransomware infection on research servers, and a data breach of student records. The university has a limited budget and must decide which risk to mitigate first. They have rated likelihood and impact on a scale of 1 to 5. The DDoS risk has likelihood 5 and impact 2, the ransomware risk has likelihood 3 and impact 5, and the data breach risk has likelihood 2 and impact 5. Using a simple likelihood × impact score, which risk should be addressed first?

    Select an answer first
  5. 5foundation · easy

    Which statement correctly describes a qualitative risk analysis method?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.