
Dell NIST Cybersecurity Framework v2.0
Domain 10Objective 3
Integrate Cybersecurity Risk Management into Broader Enterprise Risk Management Programs. NIST-CYBERSECURITY-FRAMEWORK-2 Practice Questions (Page 5)
Part of the Assess Cybersecurity Risk Communication and Integration domain, which accounts for 10% of the NIST-CYBERSECURITY-FRAMEWORK-2 exam.
28questions here
6free pages
5concepts
10%of the exam
Questions 21–25
- 21
A large retail company is updating its enterprise risk appetite statement. The CISO wants cybersecurity risk to be explicitly included. Which stakeholder group must be engaged to ensure the risk appetite statement reflects the organization's tolerance for cyber risk?
Select an answer first - 22
A company's enterprise risk committee uses a risk matrix with likelihood and impact scales. The CISO wants to ensure cybersecurity risks are assessed using the same scales. What is the best way to achieve this?
Select an answer first - 23
A financial services firm has an enterprise risk committee that oversees all risk types. The CISO wants to ensure cybersecurity risk is governed consistently with other risks. What is the most effective way to achieve this alignment?
Select an answer first - 24
A CISO needs to explain the concept of cybersecurity risk to a new enterprise risk manager who is unfamiliar with the domain. Which approach is most effective?
Select an answer first - 25
A CISO is preparing a quarterly risk report for the board. The board is interested in the top risks and the effectiveness of mitigation efforts. What is the most effective way to present this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Dell Technologies. “NIST-CYBERSECURITY-FRAMEWORK-2” is a trademark of its owner, used for identification only.