Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 3Objective 1

Explain IDENTITY Function with Its Categories and Subcategories. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 2)

Part of the NIST Framework: IDENTITY Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

33questions here
7free pages
10concepts
18%of the exam

Questions 6–10

  1. 6foundation · easy

    Which subcategory of Asset Management (ID.AM) in the NIST Cybersecurity Framework 2.0 addresses the assignment of roles and responsibilities for asset management?

    Select an answer first
  2. 7application · medium

    An online retailer relies on a third-party cloud provider for its e-commerce platform and a separate logistics vendor for order fulfillment. After a recent breach at the logistics vendor, the retailer's CISO wants to formally document the security requirements that both vendors must meet, including incident notification timelines and data protection standards. Which IDENTIFY category and subcategory best address this need?

    Select an answer first
  3. 8foundation · easy

    In the Improvement (ID.IM) category of the NIST Cybersecurity Framework 2.0, which subcategory focuses on reviewing the organization's risk management processes?

    Select an answer first
  4. 9expert · hard

    A financial institution is reviewing its supply chain risk management program. It has identified that its primary cloud provider has a significant vulnerability that could expose customer data. The institution's risk assessment shows that the likelihood of exploitation is low, but the impact would be catastrophic. The institution also has a secondary cloud provider that is less critical but has a higher likelihood of a minor incident. The CISO must decide where to focus supply chain risk management efforts. Which approach aligns with the IDENTIFY function?

    Select an answer first
  5. 10application · medium

    A university's IT security team conducts an annual review of its risk management process. They compare the previous year's risk assessment results with actual security incidents, identify gaps in their threat modeling, and update their risk register accordingly. They also revise their vulnerability scanning schedule based on lessons learned. Which IDENTIFY category is the team primarily exercising?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.