Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Dell Technologies logo

Dell NIST Cybersecurity Framework v2.0

Domain 2Objective 6

Identify and Manage Cybersecurity Risks Associated with Suppliers and Third-Party Vendors. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 5)

Part of the NIST Framework: GOVERN Function domain, which accounts for 18% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.

30questions here
6free pages
5concepts
18%of the exam

Questions 21–25

  1. 21application · medium

    A government agency is considering a vendor for cloud email services. The vendor's security assessment reveals that they do not encrypt data at rest. The agency's data classification policy requires encryption for all sensitive data. What should the agency do?

    Select an answer first
  2. 22application · medium

    A company is considering a new vendor for customer relationship management (CRM). The vendor has provided a completed security questionnaire, but the company's risk team wants to verify the answers. What is the best way to validate the vendor's security posture?

    Select an answer first
  3. 23application · medium

    A company is terminating its contract with a marketing agency that had access to customer data. The company's security team must ensure that the agency no longer has access to any company systems or data. What is the most important step in the termination process?

    Select an answer first
  4. 24application · medium

    An organization uses a third-party IT support vendor that has remote access to employee workstations. The vendor recently had a data breach that did not affect the organization. The organization's risk team wants to ensure that the vendor's security posture is still acceptable. What is the best action?

    Select an answer first
  5. 25application · easy

    A company is about to sign a contract with a new supplier that will provide raw materials and also have access to the company's inventory system for just-in-time delivery. The company's risk team has not yet assessed this supplier. What is the first step the risk team should take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.