
Dell NIST Cybersecurity Framework v2.0
Domain 8Objective 2
Explore Different Organizational Profiles. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 2)
Part of the Analyze NIST CSF Profiles domain, which accounts for 7% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
22questions here
5free pages
5concepts
7%of the exam
Questions 6–10
- 6
A financial services firm has completed both its Current and Target Organizational Profiles. The gap analysis shows that the largest gaps are in the 'Protect' Function (specifically PR.PS-01 and PR.AT-01), while smaller gaps exist in 'Recover' and 'Respond'. The firm has a limited budget and must address the most critical risks first. What should the firm do next?
Select an answer first - 7
A logistics company is developing its first Organizational Profile. The security team has completed a Current Profile that shows strong implementation of most Subcategories, but the company's risk appetite is low and the board has mandated a 'highly mature' security program. The team is now deciding what the Target Profile should reflect. What should the Target Profile be based on?
Select an answer first - 8
A healthcare organization is developing its Organizational Profile. The project manager has collected data from IT security, clinical engineering, and the privacy office. However, the manager is concerned that the profile may be incomplete because the organization's third-party vendors (e.g., a cloud EHR provider and a medical device supplier) have not been consulted. What is the most appropriate action?
Select an answer first - 9
A mid-sized bank is developing its Organizational Profile. The project team has limited time and resources. The team lead proposes to base the Current Profile primarily on existing security policies and audit reports, rather than conducting extensive new interviews. The compliance officer is concerned that this approach may miss important gaps. What is the most appropriate way to balance efficiency and accuracy?
Select an answer first - 10
A university has completed its Current and Target Organizational Profiles. The gap analysis shows that the largest gaps are in the 'Protect' Function, specifically in identity management and access control (PR.AA). The CIO needs to present the findings to the board of trustees, who are not technical and are primarily concerned with budget and risk. How should the CIO communicate the profile results?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.