
Dell NIST Cybersecurity Framework v2.0
Domain 5Objective 4
Elaborate the Tools and Techniques That Can Be Employed for Achieving Continuous Monitoring and Adverse Event Analysis. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 4)
Part of the NIST Framework: DETECT Function domain, which accounts for 7% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
22questions here
5free pages
3concepts
7%of the exam
Questions 16–20
- 16
A security analyst is investigating a series of failed login attempts followed by a successful login from an unusual IP address. The analyst must determine whether the successful login was a result of a brute-force attack or a legitimate user accessing from a new location. The organization has multi-factor authentication (MFA) enabled. Which analysis would be most decisive in determining the cause?
Select an answer first - 17
In a SOC, which combination best illustrates the integration of continuous monitoring and adverse event analysis?
Select an answer first - 18
A security operations center (SOC) has deployed a SIEM, UEBA, and a SOAR platform. The SOC is still experiencing a high number of false positives, and analysts are spending too much time investigating low-risk alerts. The SOC wants to improve the efficiency of its detection and response process. Which approach would best achieve this?
Select an answer first - 19
A security analyst is investigating an alert about a user account that was locked out multiple times in one hour. The analyst wants to determine whether this was a brute-force attack or a user error. Which adverse event analysis technique would best help the analyst make this determination?
Select an answer first - 20
A company has deployed a SIEM that collects logs from its on-premises and cloud environments. The security team wants to detect attacks that use legitimate administrative tools, such as PowerShell, for malicious purposes. They have enabled logging for PowerShell, but they are concerned about the volume of logs generated. Which approach would best balance detection capability with log management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.