
Dell NIST Cybersecurity Framework v2.0
Domain 10Objective 4
Explain the Importance of Supply Chain Risk Management (SCRM) in Cybersecurity. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 5)
Part of the Assess Cybersecurity Risk Communication and Integration domain, which accounts for 10% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
28questions here
6free pages
7concepts
10%of the exam
Questions 21–25
- 21
What is a key best practice in vendor management to reduce supply chain cybersecurity risk?
Select an answer first - 22
A company has two vendors: Vendor A provides a critical service but has a high likelihood of a security incident. Vendor B provides a non-critical service but has a low likelihood of an incident. The company has limited budget for risk mitigation. What is the most appropriate approach?
Select an answer first - 23
Which international standard focuses on security management systems for the supply chain?
Select an answer first - 24
A company has identified a critical vulnerability in a third-party component. The vulnerability is not yet publicly disclosed, and the vendor is working on a patch. The company's security team wants to inform stakeholders but is concerned about leaking sensitive information. What is the best approach?
Select an answer first - 25
A company is conducting a risk assessment of its suppliers. They have identified that a supplier has a high likelihood of a data breach due to weak security controls, but the supplier only provides non-sensitive office equipment. How should the company prioritize this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.