
Dell NIST Cybersecurity Framework v2.0
Domain 10Objective 1
Explain Cybersecurity Risks and Their Impact on Organizations. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 2)
Part of the Assess Cybersecurity Risk Communication and Integration domain, which accounts for 10% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
15questions here
3free pages
5concepts
10%of the exam
Questions 6–10
- 6
An organization is planning to migrate its customer database to a cloud provider. The CISO has identified a risk of data exposure due to misconfigured cloud storage. How should the CISO communicate this risk to the project manager who is responsible for the migration timeline?
Select an answer first - 7
A CISO needs to communicate the risk of a potential data breach to the board of directors. The board is not technical and is primarily concerned with financial and reputational impact. Which approach is most effective?
Select an answer first - 8
A financial services firm is assessing the risk of a phishing campaign targeting its employees. The firm has implemented multi-factor authentication (MFA) and security awareness training, which reduces the likelihood of successful credential theft. However, if an attacker does compromise an employee's credentials, they could access sensitive client financial data. The firm's risk manager must determine the overall risk level. Which statement best reflects the risk assessment?
Select an answer first - 9
Why is it important to communicate cybersecurity risks to different stakeholders in an organization?
Select an answer first - 10
A vulnerability in a public-facing web server has a high likelihood of exploitation and could result in a complete loss of customer data. How would this risk be characterized in terms of likelihood and severity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.