Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 5Objective 1

Explain the Categories and Subcategories of the DETECT Function. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 3)

Part of the NIST Framework: DETECT Function domain, which accounts for 7% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

26questions here
6free pages
9concepts
7%of the exam

Questions 11–15

  1. 11foundation · easy

    Which of the following is NOT one of the six categories defined under the DETECT function in the NIST Cybersecurity Framework 2.0?

    Select an answer first
  2. 12application · medium

    A healthcare organization's SIEM receives alerts from its EDR, firewall, and identity provider. The security team notices that a single user account was used to log in from two different countries within five minutes, and the same account then attempted to access a sensitive database. The team wants to determine whether these events are related. Which DETECT subcategory best describes this activity?

    Select an answer first
  3. 13application · medium

    A cloud services provider has implemented a system that automatically analyzes network traffic and user behavior, and when it detects anomalous activity, it automatically creates a ticket in the SOC's ticketing system and sends an alert to the on-call analyst. According to the NIST CSF 2.0 DETECT function, which subcategory under Detection Technology is the provider primarily implementing?

    Select an answer first
  4. 14application · medium

    A university's IT security team has documented that the SOC manager is responsible for overseeing all detection activities, the tier-1 analysts are responsible for triaging alerts, and the tier-2 analysts are responsible for deep-dive analysis. The team has also documented escalation procedures. Which DETECT subcategory does this documentation primarily support?

    Select an answer first
  5. 15application · medium

    A retail company has configured its web application firewall to send an email notification to the security team whenever a SQL injection attempt is blocked. The company also ensures that all firewall logs are retained for 90 days. According to the NIST CSF 2.0 DETECT function, which two subcategories under Detection Technology are the company exercising?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.