Pass the Isaca Isaca Certification NIST-COBIT-2019 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What does a CSF Informative Reference within the CSF Core provide?

Options:

A.

A high-level strategic view of the life cycle of an organization's management of cybersecurity risk


B.

A group of cybersecurity outcomes tied to programmatic needs and particular activities


C.

Specific sections of standards, guidelines, and practices that illustrate a method to achieve an associated outcome


Questions # 2:

Which function of the CSF is addressed by incorporating governance, risk, and compliance (GRC) elements into the implementation plan?

Options:

A.

Protect


B.

Detect


C.

Identify


Questions # 3:

Which of the following is a framework principle established by NIST as an initial framework consideration?

Options:

A.

Avoiding business risks


B.

Impact on global operations


C.

Ensuring regulatory compliance


Questions # 4:

Which of the following is the PRIMARY reason for establishing open communication between all participants and stakeholders as part of the implementation phase?

Options:

A.

To describe the high-level roadmap for achieving the vision


B.

To ensure issues can be identified and resolved


C.

To establish the sharing of information with external partners


Questions # 5:

In which CSF step should an enterprise document its existing category and subcategory outcome achievements?

Options:

A.

Step 1: Prioritize and Scope


B.

Step 3: Create a Current Profile


C.

Step 4: Conduct a Risk Assessment


Questions # 6:

During the implementation of Step 2: Orient and Step 3: Create a Current Profile, the organization's asset register should primarily align to:

Options:

A.

organizational strategy.


B.

configuration management.


C.

the security business case.


Questions # 7:

Which of the following is CRITICAL for the success of CSF Step 6: Determine, Analyze and Prioritize Gaps?

Options:

A.

Identification of threats and vulnerabilities related to key assets


B.

Experience in behavioral and change management


C.

Clear understanding of the likelihood and impact of cybersecurity events


Questions # 8:

Which role will benefit MOST from a better understanding of the current cybersecurity posture by applying the CSF?

Options:

A.

Executives


B.

Acquisition specialists


C.

Legal experts


Questions # 9:

Which of the following is MOST important for successful execution of CSF implementation Step 6 - Determine, Analyze, and Prioritize Gaps?

Options:

A.

Have management review and approve the gap analysis.


B.

Engage external experts to perform a cost-benefit analysis.


C.

Engage business and IT process owners for internal expertise.


Questions # 10:

The goals cascade supports prioritization of management objectives based on:

Options:

A.

the prioritization of enterprise goals.


B.

the prioritization of business objectives.


C.

the prioritization of stakeholder needs.


Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions