
Dell NIST Cybersecurity Framework v2.0
Domain 10Objective 3
Integrate Cybersecurity Risk Management into Broader Enterprise Risk Management Programs. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 3)
Part of the Assess Cybersecurity Risk Communication and Integration domain, which accounts for 10% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
28questions here
6free pages
5concepts
10%of the exam
Questions 11–15
- 11
Which communication approach is most effective when presenting cybersecurity risk to enterprise-level stakeholders?
Select an answer first - 12
A regional bank's enterprise risk committee meets quarterly and reviews operational, credit, and market risk. The CISO wants cybersecurity risk to be considered alongside these. The committee chair is concerned that adding a separate cybersecurity agenda item will overwhelm the meeting. What is the most effective approach for the CISO to take?
Select an answer first - 13
A healthcare organization wants to integrate its cybersecurity risk management with its enterprise risk management program. The organization already uses ISO 31000 for enterprise risk and wants a framework that aligns cybersecurity risk with that structure. Which approach best meets this need?
Select an answer first - 14
A government agency uses the NIST Risk Management Framework (RMF) for its cybersecurity program and the GAO's Framework for Managing Improper Payments for enterprise risk. The agency wants to integrate cybersecurity risk into its enterprise risk management without duplicating efforts. What is the most effective approach?
Select an answer first - 15
A utility company is planning a major cybersecurity investment. The CFO is skeptical because the ROI is unclear, and the operations director is concerned about downtime during implementation. The CISO must gain approval from the executive committee. What is the best way to engage these stakeholders?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.