
Dell NIST Cybersecurity Framework v2.0
Domain 3Objective 5
Describe Risk Assessment. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 2)
Part of the NIST Framework: IDENTITY Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
22questions here
5free pages
5concepts
18%of the exam
Questions 6–10
- 6
Which statement best describes a risk assessment as defined in the NIST Cybersecurity Framework?
Select an answer first - 7
A retail chain has completed a risk assessment and produced a risk register. The chief information security officer (CISO) wants to present the findings to the board of directors to justify the cybersecurity budget. Which output of the risk assessment would be most useful for this presentation?
Select an answer first - 8
Why is it important to prioritize risks after evaluating them?
Select an answer first - 9
A small e-commerce company is implementing the NIST Cybersecurity Framework. They want to understand their current security posture and decide where to focus limited resources. They have started by cataloging their assets, threats, and vulnerabilities. What is the primary purpose of this activity within the Identify function?
Select an answer first - 10
A regional bank is conducting its annual risk assessment. The team has identified that a legacy internet-facing application has a known unpatched vulnerability. They are now determining the potential financial loss if the vulnerability is exploited and the likelihood of exploitation based on current threat intelligence. Which step of the risk assessment process are they performing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.