
Dell NIST Cybersecurity Framework v2.0
Domain 3Objective 5
Describe Risk Assessment. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 3)
Part of the NIST Framework: IDENTITY Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
22questions here
5free pages
5concepts
18%of the exam
Questions 11–15
- 11
A multinational corporation is conducting a risk assessment for its global IT infrastructure. The risk team has historical data on the frequency of cyber incidents and the financial losses associated with each type of incident. They need to compare risks across different business units and justify investments in risk mitigation. However, some risks, such as reputational damage, are difficult to quantify in monetary terms. What is the best approach for this risk assessment?
Select an answer first - 12
In the context of the NIST Cybersecurity Framework, what is the primary purpose of a risk assessment within the Identify function?
Select an answer first - 13
A healthcare organization is conducting a risk assessment for its patient portal. The risk team has assigned a monetary value to the potential loss from a data breach and calculated the annualized loss expectancy based on the probability of occurrence. Which risk analysis method are they using?
Select an answer first - 14
A hospital is conducting a risk assessment and has identified two critical risks: a ransomware attack that could disrupt patient care systems, and a data breach of electronic health records (EHR). The ransomware risk has a likelihood rating of 4 and an impact rating of 5. The data breach risk has a likelihood rating of 2 and an impact rating of 5. The hospital has a limited budget and can only mitigate one risk this year. The risk team is divided: some argue that the ransomware risk should be prioritized because of its higher likelihood, while others argue that the data breach risk is more important because of regulatory penalties. Which approach should the hospital take to prioritize these risks?
Select an answer first - 15
A government agency is conducting a risk assessment for a new system. They need to compare risks across different departments, but they have limited historical data and the risks are difficult to quantify in monetary terms. Which risk analysis method is most appropriate for this situation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.