Dell NIST Cybersecurity Framework Free Sample Questions

20 free sample questions200 in the full practice test

Try simulator

D-CSF-SC-23 Sample Questions

  1. Question 1

    A regional bank is adopting the NIST Cybersecurity Framework and is currently in the process of developing its Framework Profile. The CISO wants to create a 'Target Profile' that aligns with a new digital transformation initiative. Which statement most accurately describes the primary purpose of this Target Profile?

    Answer and explanation

    Correct answer: C

    The Target Profile in the NIST Cybersecurity Framework is used to describe the desired cybersecurity outcomes an organization aims to achieve. It aligns cybersecurity activities with business requirements, risk tolerances, and resources. It serves as a roadmap for improvement, contrasting with the Current Profile which documents the existing state.

  2. Question 2

    Multiple answers

    A manufacturing company with extensive Industrial Control Systems (ICS) is performing an asset inventory as part of the NIST CSF Identify (ID.AM) function. Beyond standard IT assets, which of the following asset types are crucial to include for a comprehensive inventory in this specific environment? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    PLCs are fundamental components of Industrial Control Systems that control manufacturing processes. Their compromise could lead to significant physical and operational disruption, making them critical assets to inventory and protect.

    The NIST CSF defines assets to include data flows. In an ICS environment, the communication pathways between the IT and OT networks are critical choke points and potential attack vectors. Inventorying and understanding these flows is essential for risk management.

  3. Question 3

    A cybersecurity consultant is advising a company on implementing the Protect function (PR.AC) of the NIST CSF. The company has a flat network architecture and uses shared administrator accounts. To align with the principle of least privilege, the consultant recommends implementing a specific access control model. Which model assigns permissions to users based on their job titles and responsibilities within the organization?

    Answer and explanation

    Correct answer: C

    Role-Based Access Control (RBAC) is an access control model where permissions are assigned to roles, and users are then assigned to those roles based on their job functions and responsibilities. This method is highly effective for enforcing the principle of least privilege in a structured way.

  4. Question 4

    During a security assessment, a SOC analyst discovers that a critical server is communicating with a known command-and-control (C2) IP address. This discovery was made by correlating firewall logs with a third-party threat intelligence feed. Which subcategory of the Detect (DE) function is most directly demonstrated by this activity?

    Answer and explanation

    Correct answer: B

    This scenario perfectly illustrates DE.AE-2 (Anomalies and Events: Analysis). The analyst is not just looking at one data source but is aggregating (collecting) and correlating (linking) data from two distinct sources—internal firewall logs and an external threat intelligence feed—to detect a malicious event.

  5. Question 5

    A hospital's CSIRT has confirmed a data breach involving protected health information (PHI). The Incident Response Plan (IRP) calls for immediate containment. The lead incident responder is deciding between two containment strategies: isolating the affected subnet from the rest of the network versus shutting down the individual compromised systems. What is the most critical factor to consider when choosing the appropriate containment strategy in this scenario?

    Answer and explanation

    Correct answer: D

    In a healthcare environment, the primary consideration for any action, including incident containment, must be patient safety and the continuity of care. While evidence preservation and cost are important, they are secondary to ensuring that life-sustaining systems remain operational. The chosen containment strategy must balance stopping the attacker's activity with minimizing disruption to critical hospital functions.

  6. Question 6

    A cloud-native startup relies entirely on a single public cloud provider for all its operations. After a major regional outage caused by the provider, the startup's leadership decides to formalize its recovery strategy. They need a plan that specifically details the technical procedures to restore their services, either in the same region or a different one. Which document is most appropriate for this purpose?

    Answer and explanation

    Correct answer: C

    A Disaster Recovery Plan (DRP) is a technical, documented process focused on restoring IT systems and infrastructure after a disaster. It contains the specific procedures for recovery, such as failing over to a secondary region or restoring from backups. This is distinct from a Business Continuity Plan (BCP), which is broader and focuses on keeping business functions running during a disruption.

  7. Question 7

    True or False: The NIST Cybersecurity Framework Implementation Tiers are maturity levels that an organization must progress through sequentially from Tier 1 to Tier 4 to be considered compliant.

    Answer and explanation

    Correct answer: B

    This statement is false. The NIST CSF Implementation Tiers (1-Partial, 2-Risk Informed, 3-Repeatable, 4-Adaptive) are not maturity levels. They describe the rigor of an organization's risk management practices. An organization selects a target Tier based on its business needs, risk tolerance, and threat environment; there is no requirement to progress sequentially, and a higher Tier is not always better or necessary.

  8. Question 8

    A government agency is conducting a Business Impact Analysis (BIA) as part of the Identify function (ID.BE). The goal is to determine the criticality of various IT systems. The BIA team needs to define the maximum acceptable amount of data loss from a system following a disruptive event. Which metric should they establish for this purpose?

    Answer and explanation

    Correct answer: B

    The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss, measured in time (e.g., 15 minutes of data, 4 hours of data). It dictates the required frequency of backups or replication. In contrast, the Recovery Time Objective (RTO) defines how quickly a system must be restored after an outage.

  9. Question 9

    A financial institution is implementing controls for the Protect function. To comply with subcategory PR.DS-5: Protections against data leaks are implemented, the security team is evaluating several technologies. Which technology is specifically designed to identify, monitor, and prevent the unauthorized exfiltration of sensitive data from the network?

    Answer and explanation

    Correct answer: C

    Data Loss Prevention (DLP) solutions are specifically designed to enforce policies that prevent sensitive data from leaving an organization's control. They work by inspecting data in use, in motion, and at rest for content that matches predefined patterns (e.g., credit card numbers, social security numbers) and blocking or alerting on unauthorized transfer attempts.

  10. Question 10

    A security operations team is struggling with a high volume of alerts from various security tools, leading to analyst fatigue and missed incidents. To improve their detection capabilities (DE.AE), they decide to implement a system that will aggregate logs, normalize data, and use correlation rules to identify high-fidelity threats. Which type of system are they implementing?

    Answer and explanation

    Correct answer: C

    A Security Information and Event Management (SIEM) system is the core technology for addressing this problem. Its primary functions are to collect (aggregate) log and event data from diverse sources, normalize it into a common format, and apply correlation rules to identify patterns indicative of a security threat. This reduces alert fatigue by consolidating many low-level events into a single, actionable incident.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 200 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon