Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 5Objective 4

Elaborate the Tools and Techniques That Can Be Employed for Achieving Continuous Monitoring and Adverse Event Analysis. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 1)

Part of the NIST Framework: DETECT Function domain, which accounts for 7% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

22questions here
5free pages
3concepts
7%of the exam

Questions 1–5

  1. 1expert · hard

    A security analyst is investigating an alert about a user account that was used to access a sensitive database from an unusual location. The analyst has access to the SIEM, which shows the login event, but the analyst needs to determine if the account was compromised. Which analysis would be most effective in confirming or ruling out compromise?

    Select an answer first
  2. 2application · medium

    After a security incident, an analyst needs to determine the root cause of a malware infection on a server. The analyst has access to the SIEM, endpoint logs, and network captures. Which analysis technique would best help identify how the malware initially entered the environment?

    Select an answer first
  3. 3foundation · easy

    Which monitoring tool is most appropriate for detecting unauthorized changes to critical system files on a server?

    Select an answer first
  4. 4application · medium

    A manufacturing company has deployed a SIEM that collects logs from its OT (operational technology) network. The security team wants to detect cyber threats that could affect production, but they are concerned about the high volume of false positives. Which approach would best integrate monitoring and analysis to reduce false positives while maintaining detection capability?

    Select an answer first
  5. 5application · medium

    A university's IT team has deployed a SIEM that collects logs from its authentication system, firewall, and endpoints. They want to detect a multi-stage attack that starts with a phishing email, then compromises a user account, and finally moves laterally to other systems. Which approach would best enable the SIEM to detect this attack chain?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.