
Dell NIST Cybersecurity Framework v2.0
Domain 4Objective 1
Explain the PROTECT Function, Its Categories, and Subcategories. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 4)
Part of the NIST Framework: PROTECT Function domain, which accounts for 12% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
30questions here
6free pages
6concepts
12%of the exam
Questions 16–20
- 16
A healthcare organization is implementing a new policy requiring that only authorized clinical staff can access patient records, and that access is automatically revoked when a staff member transfers departments. The security team must also ensure that any access to patient data is logged for audit purposes. Which combination of controls best satisfies these requirements?
Select an answer first - 17
A large enterprise is migrating to a cloud-based identity provider. The security team is concerned about the risk of a single compromised administrator account. They want to implement a control that makes it significantly harder for an attacker to use stolen administrator credentials. Which control is most directly aligned with the Identity Management, Authentication, and Access Control (PR.AA) category?
Select an answer first - 18
A cloud service provider is responsible for securing the underlying infrastructure that hosts its customers' virtual machines. The provider must ensure that the hypervisor is hardened, and that customers cannot access each other's data. The provider also needs to maintain the availability of its services. Which set of controls is most aligned with the Platform Security (PR.PS) category?
Select an answer first - 19
A government agency is implementing a new security awareness program. The agency has a mix of technical and non-technical staff, and the security team wants to ensure that the training is effective and aligns with the NIST PROTECT function. The training must cover topics such as phishing, password hygiene, and incident reporting. The agency also wants to measure the effectiveness of the training. Which approach best aligns with the Awareness and Training (PR.AT) category?
Select an answer first - 20
A company is deploying a new line-of-business application on a fleet of Windows servers. The security team wants to ensure that only approved software can run on these servers to prevent malware and unauthorized tools. Which control is most aligned with the Platform Security (PR.PS) category?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.