
Dell NIST Cybersecurity Framework v2.0
Domain 5Objective 3
Describe the Significance of Adverse Event Analysis and Associated Security Controls in DETECT Function. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 1)
Part of the NIST Framework: DETECT Function domain, which accounts for 7% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
27questions here
6free pages
4concepts
7%of the exam
Questions 1–5
- 1
An analyst is investigating a series of alerts that appear to be related. The analyst has identified that the alerts share a common command and control (C2) server. What is the most appropriate next step in the analysis process?
Select an answer first - 2
A security analyst is reviewing a log entry that shows an unusual command executed on a server. The analyst must determine if this is an adverse event. What is the first step in the analysis process?
Select an answer first - 3
In the broader cybersecurity lifecycle, what is the role of adverse event analysis after an incident has been resolved?
Select an answer first - 4
A company wants to ensure that its security team is alerted when a user account is locked out multiple times in a short period. Which control is most appropriate?
Select an answer first - 5
A company has a limited security budget and must choose between investing in a SIEM or in endpoint detection and response (EDR) tools. The company's primary concern is detecting advanced threats that evade traditional antivirus. Which investment is more aligned with the DETECT function's goal of adverse event analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.