Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 2Objective 6

Identify and Manage Cybersecurity Risks Associated with Suppliers and Third-Party Vendors. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 1)

Part of the NIST Framework: GOVERN Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

30questions here
6free pages
5concepts
18%of the exam

Questions 1–5

  1. 1application · medium

    A regional bank is onboarding a new payment processing vendor. The vendor will handle cardholder data and connect to the bank's core systems via API. The bank's risk team needs to identify cybersecurity risks before signing the contract. Which action best supports supplier risk identification?

    Select an answer first
  2. 2application · medium

    A company has multiple vendors that provide various services. The company's risk team has identified that one vendor has a high risk due to poor security practices. The vendor is critical to operations and cannot be easily replaced. What is the best risk response?

    Select an answer first
  3. 3expert · hard

    A financial institution has a third-party vendor that provides fraud detection services. The vendor's service is critical, and any disruption could result in significant financial losses. The vendor recently experienced a major outage due to a ransomware attack. The institution's risk team must decide how to respond. What is the most appropriate action?

    Select an answer first
  4. 4application · medium

    A manufacturing company is selecting a new logistics partner that will have access to its inventory management system. The company's security policy requires that all third parties with system access undergo a security review. The logistics partner has a history of minor security incidents but offers the best operational capabilities. What should the company do?

    Select an answer first
  5. 5application · medium

    A company's risk assessment of a new vendor reveals that the vendor has a moderate risk due to lack of background checks for their employees. The vendor will have access to the company's building management system. The company decides to accept this risk. What should the company document?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.