
Dell NIST Cybersecurity Framework v2.0
Domain 6Objective 3
Gain Knowledge on Analyzing Incidents with a Focus on Controls. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 6)
Part of the NIST Framework: RESPOND Function domain, which accounts for 8% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
32questions here
7free pages
7concepts
8%of the exam
Questions 26–30
- 26
An analyst is investigating a potential data exfiltration incident. The organization uses a SIEM, but the logs from the firewall and the proxy are not correlating properly due to time zone differences. The analyst has identified a suspicious file transfer to an external IP. What is the most appropriate action to ensure accurate analysis?
Select an answer first - 27
What is the purpose of applying containment controls during incident analysis?
Select an answer first - 28
During an incident, an analyst needs to preserve evidence from a compromised server. The server is running a critical business application that cannot be taken offline for an extended period. Which control is most appropriate to preserve evidence while minimizing downtime?
Select an answer first - 29
A security analyst notices a sudden spike in outbound traffic from a single workstation to an external IP address that is not on any known threat list. The workstation also shows a new scheduled task that runs a PowerShell script. The analyst must determine if this is a real incident before escalating. Which combination of actions is most appropriate for the initial analysis?
Select an answer first - 30
Within the NIST Cybersecurity Framework 2.0 RESPOND function, what is the primary purpose of incident analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.