- Home
- All questions
All 1000 questions — CISM — Certified Information Security Manager
Every question in the free CISM — Certified Information Security Manager study material, one page each: the question, its options, the answer, the reasoning and a public source. Pick one of 4 topics or read them in order.
Challenge yourself → Study as cards
Topics
Every question
- 1. A security manager is presenting the organisation's adoption of NIST CSF 2.0 to the board. A director asks why Govern is drawn at the centre of the framework wheel rather than as the first step in a sequence. What is the most accurate explanation?
- 2. An organisation is migrating from CSF 1.1 to CSF 2.0 and the manager must brief staff on what structurally changed at the highest level of the framework. Which statement is correct?
- 3. During a governance review, the manager finds that executives have a shared but unwritten sense of how much risk is acceptable, and business units interpret it differently. Which CSF 2.0 Govern outcome is not being met?
- 4. Three business units each rate their top risk as high, but each derives that rating differently, so the executive committee cannot tell which risk deserves funding first. Which governance outcome most directly addresses this?
- 5. A manager is drafting the agenda for the quarterly cybersecurity risk discussion under CSF 2.0. Which item belongs on that agenda that a purely threat-focused agenda would omit?
- 6. After a serious incident, the board asks who is ultimately accountable for cybersecurity risk. The security manager wants to answer consistently with CSF 2.0. Which answer is correct?
- 7. A security strategy names supply chain risk as its highest priority, yet the budget allocates almost nothing to supplier assurance while funding a large endpoint refresh. Which CSF 2.0 Govern outcome is not being satisfied?
- 8. An auditor notes the organisation's information security policy was approved six years ago and has not been touched since, although the organisation has since adopted cloud hosting and entered a regulated market. What is the governance failing?
- 9. The organisation produces detailed quarterly risk performance reports, but the security strategy has never been amended in response to them. Which CSF 2.0 Govern category is not functioning?
- 10. A manager is preparing to use CSF Organizational Profiles for the first time and must explain the difference between the two profile types to the steering group. Which pairing is correct?
- 11. An organisation has completed both its Current and Target CSF Profiles. What is the next step in the CSF sequence, and what does it produce?
- 12. A mid-sized organisation in a regulated sector has limited capacity to design a Target Profile from scratch. Which CSF resource is intended to serve as its starting point?
- 13. A consultant tells the board the organisation should aim for CSF Tier 4 because higher tiers are always better. How should the security manager correct this?
- 14. An assessment finds that management has approved the organisation's risk management practices, but they are not established as organisation-wide policy. Which CSF Tier does this best describe?
- 15. At which CSF Tier would you expect executives to weigh cybersecurity risk alongside financial risk, with the organisational budget itself shaped by the predicted risk environment and risk tolerance?
- 16. In the CSF risk communication model, which description correctly matches each layer to what it contributes?
- 17. A privacy officer argues that if the organisation prevents all security incidents, it will have no privacy risk. How should the security manager respond, consistent with CSF 2.0?
- 18. A multinational asks why the CSF can be applied across its operations in several countries and industries without being rewritten for each. What property of the framework explains this?
- 19. A newly appointed security manager wants to structure risk management across the organisation using SP 800-39. Which description of the three tiers is correct?
- 20. An organisation is starting to apply SP 800-39 and asks which risk management component belongs at Tier 1 and why it must come first. What is the correct answer?
- 21. A design review proposes to complete the enterprise architecture and then add a separate information security architecture layer beside it. Why does SP 800-39 regard this as wrong?
- 22. A vulnerability discovered in one system turns out to stem from a design pattern reused across the estate. According to SP 800-39, what should follow?
- 23. The board asks the security manager for a definition of governance it can apply beyond security. Which of these matches the definition SP 800-39 uses?
- 24. A security manager is asked which outcomes a governance programme should deliver for risk management under SP 800-39. Which two are among the five named outcomes? Choose two.
- 25. In a large organisation, legal, finance, IT and security each run their own governance forum, and their decisions increasingly conflict. What does SP 800-39 advise?
- 26. An organisation is choosing between centralised, decentralised and hybrid governance models for security. Whichever model is selected, what does SP 800-39 insist upon?
- 27. A manager reads that the organisation must establish a risk executive and assumes this means recruiting an individual into a new post. How should this be corrected under SP 800-39?
- 28. Each system owner reports that risk to their own system is acceptable, yet the organisation wants to know whether risk is acceptable overall. Which role produces that view under SP 800-39?
- 29. A parent organisation must decide how much freedom its subsidiaries have to run their own risk processes. Under SP 800-39, which function specifies that degree of autonomy?
- 30. A security manager is drafting the organisation-wide risk management strategy. Which two elements does SP 800-39 expect it to contain? Choose two.
- 31. An organisation publishes a one-line risk tolerance statement on its intranet, yet staff continue to make inconsistent decisions. What does SP 800-39 say was missing?
- 32. Following a major loss, an executive argues they cannot be held responsible because they personally approved no individual risk decision. Under SP 800-39, why is this defence incomplete?
- 33. An enterprise risk officer worries that adopting SP 800-39 will duplicate the existing enterprise risk management programme. How should the security manager characterise the relationship?
- 34. An organisation must satisfy both ISO/IEC management system requirements and NIST guidance, and its manager fears running two incompatible processes. What did NIST do to reduce that burden?
- 35. A candidate is asked to define information security governance in management terms rather than technical ones. Which definition matches NIST's?
- 36. A manager is building out the organisation's security governance and wants to cover the components NIST identifies. Which two are among those components? Choose two.
- 37. A reviewer cannot tell why the security strategy contains a particular goal, because nothing links it to anything the business has stated it wants. What quality is the strategy lacking?
- 38. The security strategy is reviewed annually by calendar. Which two circumstances does NIST say should also trigger a revisit before the next annual review? Choose two.
- 39. In one organisation the security head controls the line-item budget for all security activity and every security practitioner reports into that office. Which governance structure does this describe?
- 40. A group security office writes policy and provides oversight, but each operating unit funds its own security programme and its security officers report to their unit heads. Which structure is this?
- 41. A manager benchmarks peers and finds none operate a purely centralised or purely decentralised security governance structure. What does NIST say about this observation?
- 42. An organisation is deciding how centralised its security governance should be. Which two factors does NIST name as bearing on that decision? Choose two.
- 43. Having chosen a hybrid governance structure, an organisation's leadership treats the decision as settled permanently. What does NIST say about that assumption?
- 44. A business unit head is told they are responsible for securing their operations, but they cannot approve spending, hire staff or mandate controls in their own unit. Which governance principle is breached?
- 45. An organisation appoints its network operations lead to also act as senior information security officer, alongside their existing duties. Which expectation in the NIST role definition is not met?
- 46. An assessment repeatedly finds the same deficiencies year after year, with no record of what was done about earlier findings. Which senior security officer responsibility is not being discharged?
- 47. A new senior information security officer reviews their remit. Which two duties does NIST place with that role? Choose two.
- 48. A board member asks which internal function independently assesses security practice, detects waste and misuse, and recommends how to prevent recurrence. Which role is described?
- 49. A proposed monitoring capability would improve threat detection but capture far more employee personal data than the current tooling. Which role is specifically charged with holding the balance in this decision?
- 50. Two employees commit the same policy violation, and one is dismissed while the other receives no sanction. Which role owns the practice that failed here?
- 51. A data centre review must cover controls that fall outside the information security officer's direct remit. Which two areas does NIST place with the physical security officer? Choose two.
- 52. A procurement completes without any security requirements in the contract, and the security office learns of it only at go-live. Which governance relationship failed?
- 53. An enterprise architect delivers a completed target architecture and then asks the security team to identify where controls should be added. Why is this sequence wrong under NIST guidance?
- 54. A manager must explain to a new starter what the organisation's information security policy actually is, in NIST's terms. Which description is correct?
- 55. An organisation has a governance committee, defined roles and an approved strategy, but no written security policy. Why does NIST regard this as a fundamental weakness?
- 56. A drafter builds the organisation's security policy purely from an external control framework, with no other input. Which two further inputs does NIST expect the policy to be built from? Choose two.
- 57. A security policy is reviewed and found to name roles and set a control baseline, but staff say they do not know what conduct is expected of them or what happens if they fall short. Which required element is missing?
- 58. A team issues a procedure that relaxes a requirement stated in the approved security policy, arguing the procedure is more current. How should the security manager respond?
- 59. Physical security policy grants building access on one basis while information security policy grants system access on another, and the two contradict for contractors. What does NIST advise?
- 60. A manager sets up ongoing monitoring of the security programme itself. Which two questions does NIST say that monitoring should answer? Choose two.
- 61. Policies that were entirely adequate at approval are found three years later to be inadequate although nothing was formally changed. Which cause does NIST specifically name alongside changed mission and technology?
- 62. A manager is challenged that periodic assessments are pure overhead because most come back clean. Which two additional purposes does NIST attribute to them? Choose two.
- 63. An organisation subject to several regulators finds their requirements pull in different directions on evidence and reporting. How does NIST characterise this situation?
- 64. A security manager notices that individuals with assigned security responsibilities face no consequence when they simply fail to act. Which of NIST's keys to good governance is being neglected?
- 65. Security planning happens in the security office and is presented to the business only once complete, separately from strategic and capital planning. Which NIST governance practice does this violate?
- 66. Monitoring consistently shows that one control family underperforms, but funding allocations the following year are unchanged. Which governance practice is not working?
- 67. Under IR 8286, which governance responsibility sits with executive leaders in relation to risk?
- 68. An organisation set its risk strategy three years ago and treats it as settled. According to IR 8286, why is this inadequate?
- 69. IR 8286 distinguishes two risk officer roles. Which pairing correctly describes them?
- 70. An enterprise risk steering committee wants assurance that the risk process it mandated is genuinely being applied across the business. Which role provides that?
- 71. Stakeholders in a risk process repeatedly disagree over who decides and who merely comments. Which tool does IR 8286 suggest to settle this?
- 72. An organisation assigns a large portfolio of risks to an owner who has no training or experience in that domain. What does IR 8286 say about this arrangement?
- 73. An enterprise risk committee receives risk input, but human resources, legal, audit and compliance are unaware of its work and of the subordinate councils feeding it. What does IR 8286 recommend?
- 74. A system owner proposes to decide their system's risk treatment purely on the system's own technical merits. Which two organisational factors does SP 800-37 say such decisions are also tied to? Choose two.
- 75. An organisation skips the RMF Prepare step at the organisational level and starts categorising systems immediately. Which consequences does NIST predict?
- 76. A consolidation programme reduces the number of distinct platforms in the estate. Beyond cost, what security benefit does SP 800-37 attribute to consolidation, optimisation and standardisation?
- 77. Two divisions of the same group manage risk very differently, one by top-down direction and the other by consensus among peers. What does SP 800-37 require despite this difference?
- 78. Risk management tasks are assigned but consistently go undone, and investigation shows staff were named without being funded or freed from other duties. Which requirement was not met?
- 79. A governance model pushes risk direction downward from the organisation to systems, but nothing flows back up. What does the NIST multi-level model require?
- 80. A manager must explain what an authorisation boundary determines. Which answer is correct?
- 81. A manager must define trust for a governance paper on external partnerships, using SP 800-39's meaning. Which definition is correct?
- 82. A partner is trusted to handle routine scheduling data but the same partner is not trusted with regulated health records. Which property of trust does this illustrate?
- 83. A supplier the organisation trusts subcontracts part of the work to a firm the organisation has never assessed, and argues that its own trusted status should carry over. Which property of trust rebuts this?
- 84. A due diligence report claims a supplier's trustworthiness cannot be evaluated because trust is subjective. How should the security manager respond under SP 800-39?
- 85. A business unit wants to establish a data-sharing partnership and treats the trust decision as a commercial matter outside the risk process. How does SP 800-39 characterise such a decision?
- 86. An organisation is preparing to rely on an external service provider. Which two things does SP 800-39 say it must establish? Choose two.
- 87. A risk assessment of partners considers only competitors and known adversaries as sources of concern. Which category does SP 800-39 warn is being missed?
- 88. Two organisations in a partnership want to build trust through transparency about risk. Which two mechanisms does SP 800-39 describe for achieving that? Choose two.
- 89. A security architecture allocates controls so that a failure of any one layer is covered by another, and so that similar protections come from diverse sources. Which two concepts does SP 800-39 name for this? Choose two.
- 90. Two years after an architectural decision, nobody can explain why a particular risk trade-off was made. Which SP 800-39 practice would have prevented this?
- 91. A project plans to gather functional requirements first and add security requirements once the design is stable. Why does SP 800-39 object?
- 92. A requirements document lists the security functions a system must provide but says nothing about how much assurance is needed in them. What has been omitted under SP 800-39?
- 93. A system cannot achieve the level of trustworthiness needed from its technical controls alone. What does SP 800-39 say the organisation should do?
- 94. A board paper argues resilience is a technical property of no interest to executives. How does SP 800-39 frame resilience?
- 95. A technology the business insists on adopting carries vulnerabilities that no available control adequately addresses. Which response does SP 800-39 identify for this situation?
- 96. A manager is aligning security activities to the system development life cycle. Which sequence of phases does NIST describe?
- 97. A programme treats its life cycle as strictly one-directional, refusing to revisit earlier phases. What does NIST say about this?
- 98. Servers are being retired and sent for disposal. Which two actions does SP 800-39 expect at this life cycle phase? Choose two.
- 99. A system is about to go live and the project manager proposes assessing control effectiveness after six months of operation. Why does SP 800-39 place that assessment earlier?
- 100. A security manager is told to justify why security investments must be ranked rather than all funded. Which reasoning matches NIST's capital planning guidance?
- 101. An investment management model has three phases. Which set correctly names them and their focus?
- 102. In the Select phase of investment management, on which three criteria are projects analysed and ranked before a portfolio is chosen?
- 103. A programme discovers cost overruns only at delivery. Which investment phase and mechanism was intended to catch them earlier?
- 104. Security drivers differ across the investment life cycle. Which two pairings are correct? Choose two.
- 105. An organisation begins the seven-step process for integrating security into capital planning. What is the first step?
- 106. Which two criteria does NIST use to prioritise potential enterprise-level security investments in the capital planning process? Choose two.
- 107. When assembling a security investment portfolio, several priorities compete: an internal modernisation goal, a departmental preference, and a statutory obligation. Which does NIST say ranks highest?
- 108. A security manager wants weaknesses found during assessment to actually attract funding. Which mechanism does NIST describe for connecting the two?
- 109. A manager defines the purpose of the organisation's risk monitoring. Which two purposes does SP 800-39 name? Choose two.
- 110. At the organisation tier, what kind of monitoring activity does SP 800-39 describe as appropriate?
- 111. An organisation sets every monitoring activity to an annual cadence regardless of subject. Which three inputs does SP 800-39 say should shape monitoring frequency instead?
- 112. A risk assessment established a likelihood threshold for a particular threat. How can monitoring use that threshold, according to SP 800-39?
- 113. Before choosing among risk responses, a manager lists the constraints already fixed by framing. Which two does SP 800-39 name? Choose two.
- 114. A risk register records only risks the organisation faces today. Which category does SP 800-39 say is also in scope?
- 115. A manager must explain what risk framing produces. What is its principal output under SP 800-39?
- 116. At the organisation tier, senior leaders define the risk frame. Which two aspects of monitoring do they settle there? Choose two.
- 117. An organisation has never articulated its assumptions, constraints, tolerance or trade-offs for risk. What consequence does SP 800-39 predict?
- 118. Two divisions of the same organisation hold materially different risk tolerances, grounded in their different operating realities. What does SP 800-39 say leadership should do?
- 119. Which two organisational realities does SP 800-39 say shape how an organisation frames risk? Choose two.
- 120. An organisation wants to begin risk framing. What does SP 800-39 identify as the key precondition?
- 121. While developing response options, a team finds a promising approach that the organisation's stated constraints had ruled out entirely. What does SP 800-39 say should happen?
- 122. Monitoring shows the organisation is routinely carrying far more risk than its published tolerance statement allows, with no adverse consequence to date. What does SP 800-39 say this may indicate?
- 123. An organisation with a hybrid governance structure asks how many risk assessment methodologies it should use. What does SP 800-39 suggest is appropriate?
- 124. An organisation whose culture prizes divisional autonomy does not want to mandate one risk methodology. Which approach does SP 800-39 offer?
- 125. A threat assumptions document lists the threat sources the organisation's controls are designed to address. What does SP 800-39 say it should also record?
- 126. An organisation wants to be able to roll up risk assessment results from many business areas into an organisation-wide view. What does SP 800-39 say makes this possible?
- 127. A programme manager complains that early-phase threat analysis is less specific than the analysis done nearer deployment. How does SP 800-39 characterise this?
- 128. An assessment scopes vulnerabilities to weaknesses in assets the organisation owns and controls. Which class of vulnerability does SP 800-39 say is being missed?
- 129. SP 800-39 describes impact being felt at three levels. Which set matches?
- 130. Personal data exposed by the human resources function damages the whole organisation's reputation, while also making it easier for an attacker to defeat authentication on many systems. Which point does SP 800-39 illustrate with such an example?
- 131. An organisation wants to reuse one division's risk assessment results in another division. Which two factors determine how far that reuse is legitimate? Choose two.
- 132. A decentralised organisation performs most risk assessment at the business process tier. What does SP 800-39 say this creates a greater need for?
- 133. A manager must justify the effort of keeping risk assessments current rather than repeating them from scratch each year. Which two benefits does SP 800-39 name? Choose two.
- 134. SP 800-39 distinguishes two lighter forms of reassessment. Which pairing is correct?
- 135. A team must assess risk before the organisation has finished defining its risk frame. What does SP 800-39 permit and warn?
- 136. Which two kinds of vulnerability does SP 800-39 say are identified most effectively at the organisation tier rather than lower down? Choose two.
- 137. An organisation prioritises remediating system-level flaws over addressing a weakness in its business process design. What does SP 800-39 warn about that ordering?
- 138. Two comparable organisations run the same assessment process, but one consistently surfaces far more threat and vulnerability information from its own staff. Which factor does SP 800-39 identify as the likely cause?
- 139. An assessment examines only those threats for which the organisation already has safeguards deployed. What does SP 800-39 say is missing?
- 140. Two experienced assessors reach different risk conclusions from the same evidence. How does SP 800-39 treat this outcome?
- 141. A manager considers using a panel of assessors with varied backgrounds. Which two effects does SP 800-39 attribute to that diversity? Choose two.
- 142. A candidate asks how the CISM examination is structured. Which description is correct?
- 143. Which two statements about the weighting of CISM domains are correct? Choose two.
- 144. CISM Domain 1 is divided into two parts. Which pairing is correct?
- 145. Under CISM's enterprise governance subtopic, which two subjects are examined? Choose two.
- 146. CISM examines strategic planning within the information security strategy subtopic. Which three concerns does it specifically name?
- 147. A manager is about to draft a new information security strategy. Which CISM task should come before the strategy itself is written?
- 148. An organisation runs its security governance as a separate structure with its own committees, reporting lines and calendar, parallel to corporate governance. Which CISM task is not being fulfilled?
- 149. In the CISM document hierarchy, what is the stated relationship between policies and standards, procedures and guidelines?
- 150. A security manager argues that justifying funding is the finance function's job, not theirs. How does the CISM job practice treat this?
- 151. An organisation secured executive sign-off for its security strategy at launch and has not revisited that support since. Which CISM task is incompletely performed?
- 152. Which two reporting duties does the CISM job practice assign to the security manager? Choose two.
- 153. A manager assumes that meeting the organisation's own internal policy is sufficient to satisfy CISM's compliance expectations. What does the job practice require in addition?
- 154. An implementation team treats every CSF subcategory as a mandatory action item to be ticked off. Why is this a misreading of the framework?
- 155. Which two of the following are categories within the CSF 2.0 Govern function? Choose two.
- 156. An organisation files its legal, regulatory and contractual cybersecurity obligations under its compliance programme and nowhere else. Where does CSF 2.0 locate that outcome?
- 157. Under CSF 2.0, screening at hiring, onboarding and departure processes for staff are addressed under which Govern category?
- 158. An organisation wants separate CSF Profiles for its payments platform and for its ransomware readiness. Is this consistent with the framework?
- 159. CSF 2.0 supplies two kinds of supplementary online resource. Which pairing describes them correctly?
- 160. Which two activities does SP 800-39 place at Tier 2, the mission and business process level? Choose two.
- 161. Senior leaders working with the risk executive function must settle three things about risk decisions. Which of these is one of them?
- 162. A manager is asked to state the purpose of information security governance in one sentence for the annual report. Which formulation matches NIST's?
- 163. A security programme definition names its mission, vision, goals and objectives, and sets out a high-level plan with short and mid-term targets. Which element does NIST say is still missing?
- 164. A security manager wants to reorganise security governance in a way the wider organisational structure does not support. What does NIST observe about such situations?
- 165. Which two responsibilities does NIST assign to the chief information officer in the security governance model? Choose two.
- 166. Which two duties does NIST place with the senior information security officer? Choose two.
- 167. Which role reviews the cost goals of each major security investment and passes investment assessments to the investment review board?
- 168. An organisation declines to share any information with a partner because it cannot establish complete trust. How does SP 800-39 characterise this position?
- 169. What benefit does SP 800-39 attribute to embedding the organisation's risk management strategy within its enterprise architecture?
- 170. During design, an assessment shows a proposed component carries known weaknesses that a comparable alternative does not. What does SP 800-39 identify as the advantage of switching at this point?
- 171. A team debating a risk rating cannot agree because they are weighing threat capability, control maturity and asset value simultaneously. Under SP 800-30, which two factors is risk actually a function of?
- 172. A manager plans to complete a risk assessment and then hold a separate exercise to rank the results. How does SP 800-30 define the scope of assessment?
- 173. An auditor asks the security manager to describe the organisation's risk assessment methodology. Which two components does SP 800-30 say it should contain? Choose two.
- 174. A team is about to begin a specific risk assessment and proposes selecting the methodology as their first activity. What does SP 800-30 say about when the methodology is settled?
- 175. An organisation relies on a three-year-old risk assessment because nothing formally changed. Why does SP 800-30 regard the validity of any assessment as bounded in time?
- 176. Which set correctly lists the typical risk factors in the NIST risk model?
- 177. A threat catalogue lists only deliberate attacks by outsiders. Which two further categories of threat source does SP 800-30 identify? Choose two.
- 178. A provisioning server goes offline and the team assumes an attack. Which point does SP 800-30 make about attributing a threat event to a single cause?
- 179. How does SP 800-30 characterise a threat source?
- 180. An assessment must estimate whether a particular adversary will initiate an attack. Which three adversary characteristics does SP 800-30 assess?
- 181. An analyst wants to model how a breach would actually unfold rather than listing isolated events. Which SP 800-30 construct is designed for this?
- 182. After a new control is deployed, the adversary begins attacking at a different time of day and against a less protected system. Which SP 800-30 concept describes this behaviour?
- 183. Which two observations does SP 800-30 make about how sophisticated adversaries behave when they meet defences? Choose two.
- 184. A team restricts its vulnerability register to software defects. Which broader definition does SP 800-30 give?
- 185. A manager assumes every vulnerability results from an omission at build time. Which two origins does SP 800-30 identify? Choose two.
- 186. Controls assessed as effective at deployment are found to be much less effective five years later, without any change being made to them. What does SP 800-30 conclude from this tendency?
- 187. Which two of the following does SP 800-30 recognise as vulnerabilities in governance structures themselves? Choose two.
- 188. The same technical vulnerability is rated critical on one system and low on another. Why is this consistent with SP 800-30?
- 189. A data centre sits on a flood plain, and a separate system has no network connectivity at all. Which SP 800-30 concept do both illustrate?
- 190. An organisation runs no database management system anywhere in its estate. What does SP 800-30 say about its exposure to SQL injection?
- 191. An analyst has a long list of individual weaknesses, each rated low. Why does SP 800-30 recommend also analysing them together?
- 192. Which two estimates does SP 800-30 combine into the overall likelihood of a threat event? Choose two.
- 193. An analyst must estimate the likelihood of a hardware failure rather than an attack. Which basis does SP 800-30 prescribe?
- 194. A likelihood rating of high is recorded with no period attached. Which requirement of SP 800-30 has been overlooked?
- 195. How does SP 800-30 distinguish the likelihood of impact from the magnitude of impact?
- 196. An analyst proposes mapping every threat to every vulnerability one-to-one across the estate. What does SP 800-30 warn about this approach?
- 197. Which four consequences does SP 800-30 use to define the level of impact from a threat event?
- 198. An asset register lists only systems, facilities, people and equipment. Which class of asset does SP 800-30 say is also in scope?
- 199. An organisation has never formally stated which impacts matter most. Which two sources does SP 800-30 say priorities can usually be derived from? Choose two.
- 200. An organisation declares that threat events whose impact falls below a stated value receive no further analysis. Is this consistent with SP 800-30?
- 201. At which tiers does SP 800-30 say risk aggregation is mainly performed?
- 202. Several moderate risks materialise in the same quarter and the combined loss exceeds anything the organisation had assessed. Which limitation of risk aggregation does this illustrate?
- 203. When aggregating risks, an analyst treats each entry as independent. Which relationship does SP 800-30 ask them to consider?
- 204. Which two sources of uncertainty in risk evaluation does SP 800-30 identify? Choose two.
- 205. An analyst wants to convey that a risk estimate is uncertain without abandoning the estimate. Which two techniques does SP 800-30 suggest? Choose two.
- 206. An organisation must compare the cost-effectiveness of several competing risk responses. Which assessment approach does SP 800-30 say supports this best?
- 207. A quantitative risk model produces precise figures, but several of its inputs were expert guesses recorded as point values. What does SP 800-30 say about this?
- 208. An organisation uses a five-level qualitative scale and finds it cannot decide which of eleven high risks to fund first. Which limitation of qualitative assessment does this show?
- 209. Two experienced assessors assign very different qualitative ratings to the same scenario. Which two remedies does SP 800-30 offer? Choose two.
- 210. An organisation scores risks from 0 to 100 but states the numbers carry no meaning outside the assessment. Which approach is this?
- 211. Which comparison does a semi-quantitative scale allow that a purely qualitative one cannot express?
- 212. SP 800-30 names three analysis orientations. Which set is correct?
- 213. An analysis begins with the consequences the organisation most fears and its critical assets, drawing on business impact analysis results, then works back to the threats that could cause them. Which orientation is this?
- 214. A team has completed a thorough threat-oriented analysis. Why does SP 800-30 recommend running a second orientation as well?
- 215. Which two many-to-many relationships does SP 800-30 identify in risk analysis? Choose two.
- 216. Which two graph-based techniques does SP 800-30 name for generating and bounding threat scenarios? Choose two.
- 217. A manager wants to be able to compare this year's risk assessment against last year's to see trends. Which property must the assessment have?
- 218. An organisation assesses risk system by system and is surprised by an exposure created by interconnections between systems. Which weakness does SP 800-30 identify in this practice?
- 219. A newly discovered vulnerability requires an organisation-wide mitigation mandate. How does this fit SP 800-30's observation about the pace of risk management at different tiers?
- 220. Which two examples does SP 800-30 use to show that risks and responses run on different time scales? Choose two.
- 221. Early in a system's life, little is known about threats or control effectiveness. What does SP 800-30 say about the risk model used at that point?
- 222. A vendor offers a single fixed risk model with fixed factors, scales and combining algorithm, claiming it suits any organisation. What does NIST say?
- 223. Which two authorisation decisions can risk assessment results support, according to SP 800-30? Choose two.
- 224. A business process depends entirely on a system that cannot be adequately protected within budget. Which response does SP 800-30 identify as sometimes the most effective?
- 225. Which sequence correctly names the four components of the SP 800-39 risk management process?
- 226. A risk frame documents the organisation's assumptions and its tolerance. Which two further elements does SP 800-39 require? Choose two.
- 227. Which four things does the assessment component of SP 800-39 identify?
- 228. SP 800-39 lists five risk responses. Why does it list sharing and transferring separately rather than treating them as one?
- 229. Which two purposes does risk monitoring serve under SP 800-39, beyond confirming that planned responses were implemented? Choose two.
- 230. A vulnerability register covers only information systems. Which two further locations does SP 800-39 say organisational vulnerabilities can occupy? Choose two.
- 231. New legislation obliges the organisation to deploy a specific safeguard immediately. Under SP 800-39, what may happen to the normal sequence of risk components?
- 232. How does SP 800-39 define risk tolerance, and where is it determined?
- 233. A consultant asserts there is an objectively correct level of risk tolerance for an organisation of a given size. How does SP 800-39 characterise risk tolerance?
- 234. Two organisations scope their threat analysis differently: one considers only threats its peers have actually suffered, the other adds threats that are merely plausible. What best explains the difference?
- 235. Two organisations adopt the same technology, but one demands far more assessment before deployment. Which factor does SP 800-39 identify as the cause?
- 236. Which two costs does SP 800-39 attribute to the extremes of risk tolerance? Choose two.
- 237. A residual risk accepted two years ago is still recorded as acceptable, and nobody has revisited it. Why does SP 800-39 regard that as a problem?
- 238. An organisation maps only the risks its suppliers pose to it. Which point does SP 800-39 make about external risk relationships?
- 239. How does SP 800-39 characterise an advanced persistent threat, and what does it say about supply chain risk in that context?
- 240. Which two channels does SP 800-39 name for exchanging threat and vulnerability information with parties outside the organisation? Choose two.
- 241. Under CSF 2.0, which combination of factors is used to understand inherent risk and rank which responses come first?
- 242. An organisation approves exceptions to policy in a change ticket and takes no further action. Which CSF 2.0 expectation is not being met?
- 243. A supplier's hardware is verified for authenticity and integrity only after it has been racked and connected. Which CSF 2.0 outcome does this fail?
- 244. CSF 2.0 names four responses for negative risk and four for positive risk. Which two are the positive-risk responses? Choose two.
- 245. An organisation applies the same assurance questionnaire to every one of its 900 suppliers and cannot complete the programme. Which CSF 2.0 outcome would address this?
- 246. A supplier is onboarded and the first security review takes place six months into the contract. Which CSF 2.0 outcome does this arrangement miss?
- 247. A supplier contract ends and the supplier retains administrative access and copies of organisational data for months afterwards. Which CSF 2.0 outcome addresses this?
- 248. A researcher reports a flaw in the organisation's public application and receives no acknowledgement for weeks because no route exists to handle such reports. Which CSF 2.0 outcome is missing?
- 249. Which sequence correctly describes the enterprise risk management life cycle used in IR 8286?
- 250. A programme schedules stakeholder communication as a discrete step after risk prioritisation. How does IR 8286 position communication in the life cycle?
- 251. What is the stated purpose of the monitoring step in the IR 8286 risk life cycle?
- 252. Which two items does IR 8286 say a risk register typically contains, beyond a description of the risk? Choose two.
- 253. An enterprise risk register holds legal and financial risks but no cybersecurity entries, and the board cannot see cyber risk alongside the rest. What does IR 8286 prescribe?
- 254. In the IR 8286 risk register, what does the term exposure denote, and what do other frameworks call the same thing?
- 255. A register entry reads simply 'ransomware'. Which form does IR 8286 recommend for a risk description?
- 256. IR 8286 distinguishes two roles attached to a register entry. Which pairing is correct?
- 257. Three business units each maintain a risk register using their own categorisation scheme. What consequence does IR 8286 identify?
- 258. IR 8286 prefers current risk to inherent risk in its register template. What reasoning does it give?
- 259. Which pairing correctly distinguishes residual risk from target residual risk in IR 8286?
- 260. Which two kinds of information does IR 8286 say a risk detail record holds that the register itself does not? Choose two.
- 261. Which two dates does IR 8286 say a risk detail record should carry? Choose two.
- 262. Which four elements does IR 8286 say a complete risk scenario describes?
- 263. IR 8286 warns two kinds of control must not be confused. Which pairing describes them correctly?
- 264. According to IR 8286, security controls respond to cybersecurity risk in four ways. Which set is correct?
- 265. Which two activities does IR 8286 say a cybersecurity risk register should support to condition its data for the enterprise view? Choose two.
- 266. A board proposes eliminating all cybersecurity risk from the organisation's operations. How does IR 8286 characterise both extremes of this spectrum?
- 267. A team applies a standard control set to every new device as a matter of course. Which practice does IR 8286 criticise here?
- 268. Controls have been deployed to treat a risk, and the register records the treatment as complete. Which follow-up does IR 8286 say is usually missing?
- 269. System-level risk data reaches the board as an unchanging red heatmap, and the board reports it cannot use it. How does IR 8286 explain this common failure?
- 270. A risk committee treats cybersecurity risk as a self-contained category with no bearing on other enterprise risks. Which example does IR 8286 use to challenge that view?
- 271. Two comparable organisations receive the same system-level risk data, but one translates it into enterprise understanding far more readily. Which structural difference does IR 8286 identify?
- 272. An organisation cannot say with confidence which devices it operates or where its data resides. What consequence does IR 8286 draw?
- 273. IR 8286 divides risk context into two parts. Which pairing is correct?
- 274. How does IR 8286 relate the risk assessment report to the cybersecurity risk register?
- 275. An organisation completes its risk register once and files it. Which point does IR 8286 make about how a register derives its value?
- 276. Which definition of risk appetite does IR 8286 adopt, and at what level is it set?
- 277. A programme drafts detailed operational risk tolerance statements before any appetite has been agreed. Which sequencing does IR 8286 describe?
- 278. Business units report risk levels on incompatible scales, so the enterprise cannot compare them. Which leadership responsibility does IR 8286 identify as missing?
- 279. Which definition of inherent risk does IR 8286 quote?
- 280. After treatment, actual residual risk is measured higher than the target residual risk that was set. What does this indicate under IR 8286?
- 281. Which two of the four inputs to cybersecurity risk identification does IR 8286 name? Choose two.
- 282. A risk identification exercise works only outward from technical scans of infrastructure. Which complementary direction does IR 8286 recommend?
- 283. A finance team values a research database at its replacement cost. Which broader view of asset value does IR 8286 take?
- 284. An analyst decides unilaterally which assets count as critical. What does IR 8286 say is needed for that determination?
- 285. An organisation already maintains business impact analysis records for continuity planning. Which further use does IR 8286 suggest for that template?
- 286. Which two cognitive biases does IR 8286 name as distorting threat modelling? Choose two.
- 287. A risk workshop spends most of its time on an attack type recently covered heavily in the press, though it is rare in the organisation's sector. Which bias does IR 8286 describe?
- 288. Which two symptoms does IR 8286 attribute to overconfidence in risk work? Choose two.
- 289. Which technique does IR 8286 name for surfacing opportunities arising from organisational strengths alongside threats reflecting weaknesses?
- 290. A register holds separate entries for a website outage and a help desk outage. What does IR 8286 say may also be needed?
- 291. An organisation records only the immediate effect of each risk event. Which analysis does IR 8286 say is also required?
- 292. Which of these does IR 8286's definition of vulnerability include, alongside an unpatched software flaw?
- 293. An analyst records a serious vulnerability for which no credible threat exists in the organisation's environment. Which two points does IR 8286 make? Choose two.
- 294. An organisation relies wholly on automated scanning to find weaknesses. Which limitation does IR 8286 note?
- 295. A stakeholder submits the risk 'I'm concerned about a denial-of-service attack'. Why does IR 8286 say this cannot be analysed as written?
- 296. A threat event assessed as highly likely nevertheless produces only minor consequences when it occurs. Which explanation does IR 8286 offer?
- 297. In which two circumstances does IR 8286 say qualitative analysis is most useful? Choose two.
- 298. On what two things does the quality of a quantitative risk analysis depend, according to IR 8286?
- 299. Which two external sources does IR 8286 suggest for improving the quality of qualitative analysis? Choose two.
- 300. A manager proposes switching the whole organisation from qualitative to quantitative risk analysis immediately. Which offsetting cost does IR 8286 identify?
- 301. The same payroll server outage is assessed as far more damaging in one week than another. Which factor does IR 8286 use this to illustrate?
- 302. An impact estimate counts only the direct loss of availability from an outage. Which two consequences does IR 8286 warn this omission produces? Choose two.
- 303. Which two secondary losses does IR 8286 give as examples following a telecommunications outage that takes a web server offline? Choose two.
- 304. Which two techniques does IR 8286 name for estimating the probability that a risk event will occur? Choose two.
- 305. Which description matches Monte Carlo simulation as IR 8286 defines it?
- 306. IR 8286 says tangible and less tangible impacts are connected in both directions. Which pair of statements captures that connection?
- 307. An estimate of likelihood and impact takes credit for every control listed in the control catalogue. What caution does IR 8286 give?
- 308. Business units estimate likelihood over different periods — one over a year, another over five. What problem does IR 8286 identify?
- 309. An organisation decides very low exposure risks need not be entered on the register. What condition does IR 8286 attach to such a threshold?
- 310. Stakeholders in different units assign different priorities to risks with identical exposure values. Which governance step does IR 8286 say prevents this?
- 311. A team sets itself the objective of driving every recorded risk to zero. How does IR 8286 state the actual goal of risk response?
- 312. An organisation deploys multi-factor authentication to reduce an access control risk and sees a rise in help desk load and user workarounds. Which point does IR 8286 make about risk responses?
- 313. A risk sits inside tolerance and the owner records the response as accept, then closes the entry and stops tracking it. Which part of the accept response has been dropped?
- 314. An organisation buys cyber insurance and treats the underlying risk as fully addressed. Which limitation does IR 8286 identify?
- 315. No cost-effective control can bring a particular risk within tolerance. Which response does IR 8286 identify, and what must be weighed alongside it?
- 316. Which two kinds of effect does IR 8286 include within mitigation? Choose two.
- 317. An organisation lacks the in-house expertise to recover from a serious cyber attack and cannot justify hiring for it permanently. Which mechanism does IR 8286 describe for this situation?
- 318. Which two control types does IR 8286 name alongside preventative, detective and corrective? Choose two.
- 319. A warning banner and a stated intention to prosecute unauthorised access are deployed. Which control type does IR 8286 classify these as?
- 320. How does IR 8286 define a corrective control?
- 321. Controls have been deployed to mitigate a risk and the register is updated to show the risk as treated. What further step does IR 8286 require before that treatment can be relied upon?
- 322. After treatment, residual risk remains above the acceptable level and further controls would cost more than the activity is worth to the business. Which option does IR 8286 point the risk owner toward?
- 323. A potential breach of design plans is estimated to cost 750,000 while full disk encryption and remote tracking would cost 275,000. Which conclusion follows from the cost-benefit reasoning IR 8286 describes?
- 324. A mitigation cannot be implemented immediately because the necessary resources are unavailable. Which two things does IR 8286 say the corrective action plan records? Choose two.
- 325. The window in which a particular risk could have occurred has now passed and its risk reserve is unspent. What does IR 8286 say should happen, and what does it require?
- 326. Which four risk factors does SP 800-37 identify as considered during risk assessment?
- 327. Which two activities belong to the preparation step of a risk assessment under SP 800-30? Choose two.
- 328. How does SP 800-30 distinguish the purpose of an initial assessment from that of a reassessment?
- 329. Which two events does SP 800-30 name as triggers for a reassessment of risk? Choose two.
- 330. Which two questions does establishing the scope of a risk assessment answer, under SP 800-30? Choose two.
- 331. An assessment team decides for itself how wide the assessment will be. Who does SP 800-30 say determines the scope?
- 332. Why does SP 800-30 expect a policy-level risk assessment to remain valid longer than one supporting a compensating control on a system?
- 333. An assessment reuses threat data gathered three years ago for a different exercise. Which consideration does SP 800-30 raise?
- 334. A system-level assessment must decide whether to include weaknesses in the controls the system inherits. What does SP 800-30 say about this choice?
- 335. Which two benefits does SP 800-30 attribute to making assumptions and constraints explicit? Choose two.
- 336. Which two constraints on a risk assessment does SP 800-30 identify? Choose two.
- 337. An organisation must assess a threat about which very little credible information exists. What effect does SP 800-30 say the resulting uncertainty may have?
- 338. Two organisations differ on whether a threat event must have been observed before it is assessed. What does SP 800-30 say about this?
- 339. Why does SP 800-30 require organisations to give guidance on identifying and compensating for uncertainty in individual risk factors?
- 340. Assessing an advanced persistent threat, an organisation must choose a stance on likelihood. Which two stances does SP 800-30 present as the ends of that range? Choose two.
- 341. What does SP 800-30 call the combination of the assessment approach and the analysis approach?
- 342. Which two circumstances does SP 800-30 say warrant greater analytical detail? Choose two.
- 343. Which two internal sources does SP 800-30 name as providing insight into both threats and vulnerabilities? Choose two.
- 344. An organisation subscribes to several external threat feeds and ingests all of them without filtering. Which three qualities does SP 800-30 say should be weighed?
- 345. A business process assessment has just been completed. What does SP 800-30 say can be done with that report at other tiers?
- 346. How does SP 800-30 describe the role of security categorisation within risk assessment?
- 347. Business owners list the shared services they currently depend on. Which further category does SP 800-30 urge them to identify?
- 348. Why does SP 800-30 ask that an organisation-specific risk model include or be translatable into the standard risk factors?
- 349. A risk model defines its factors and scales but leaves how they combine to the assessor's judgement each time. What does SP 800-30 say a model requires, and what do those rules reflect?
- 350. An organisation looks in SP 800-30 for the formula to combine semi-quantitative values and cannot find one. What is the reason NIST gives?
- 351. Is it acceptable under SP 800-30 for an organisation to use qualitative values for low-impact systems and a granular numeric scale for high-impact ones?
- 352. What is the stated objective of the conduct step of a risk assessment under SP 800-30?
- 353. Which sequence correctly orders the tasks of conducting a risk assessment under SP 800-30?
- 354. A team completes vulnerability identification and discovers weaknesses that suggest attack paths nobody had listed as threat events. What does SP 800-30 say about this?
- 355. An assessment cannot cover the whole threat space in the detail the methodology describes within the resources available. What compromise does SP 800-30 permit?
- 356. An organisation begins its risk assessment with a business impact analysis at the upper tiers rather than with threat identification. Is this consistent with SP 800-30?
- 357. How does SP 800-30 characterise non-adversarial threat sources, in contrast to adversarial ones?
- 358. Which two broader considerations does SP 800-30 suggest when viewing adversarial threat sources? Choose two.
- 359. Which kind of threat event does SP 800-30 say is of particular interest at the business process tier?
- 360. How does SP 800-30 link the relevance values an organisation assigns to threat events with its risk tolerance?
- 361. Two organisations receive the same unconfirmed threat report. The more risk-tolerant one sets it aside. How does SP 800-30 explain this?
- 362. Which organisation-tier vulnerability does SP 800-30 illustrate with the example of subverted components entering the estate?
- 363. A newly identified vulnerability has not yet been through risk assessment, so its severity is unknown. Which interim proxy does SP 800-30 permit?
- 364. Why does SP 800-30 ask organisations to assess how pervasive a predisposing condition is?
- 365. An estate has tens of thousands of individual vulnerabilities and cataloguing each would exhaust the assessment budget. Which approach does SP 800-30 permit?
- 366. Which two circumstances does SP 800-30 say mean an adversary is not expected to initiate a threat event? Choose two.
- 367. A threat event is identified for which no vulnerability or predisposing condition can be found. What does SP 800-30 direct?
- 368. Why does SP 800-30 require a rationale to accompany each likelihood assessment?
- 369. For a non-adversarial threat event, which two attributes of the event itself does SP 800-30 say the likelihood of adverse impact takes into account? Choose two.
- 370. An assessor proposes restating the organisation's risk tolerance and constraints in full within every individual risk assessment report. What does SP 800-30 say?
- 371. SP 800-39 distinguishes a course of action from a risk response measure. Which pairing is correct?
- 372. An organisation's policy states only low risks may be accepted. How does SP 800-39 describe the scope of acceptance?
- 373. An organisation maintains a single combined asset list. Which two further inventories does CSF 2.0 expect to be maintained separately? Choose two.
- 374. A team ranks assets purely by replacement cost. Which basis does CSF 2.0 prescribe for prioritising assets?
- 375. An access review confirms permissions are enforced technically but finds no policy defining them and no periodic review. Which two elements of the CSF 2.0 outcome are missing? Choose two.
- 376. An organisation delivers one annual awareness module to everyone including its security engineers and developers. Which CSF 2.0 expectation is unmet?
- 377. A data protection programme addresses data at rest and data in transit. Which two further outcomes does CSF 2.0 name under Data Security? Choose two.
- 378. An organisation adopts a secure development standard and considers the outcome achieved. Which further expectation does CSF 2.0 attach?
- 379. Security expectations are communicated to suppliers verbally at kickoff meetings and recorded in no agreement. Which CSF 2.0 outcome does this fail?
- 380. An organisation monitors its own networks and endpoints continuously but performs no monitoring of the managed service provider operating part of its estate. Which CSF 2.0 outcome is missing?
- 381. Which pairing correctly describes a common control and a common control provider in NIST usage?
- 382. Which two decisions taken at the organisation tier does SP 800-39 say constrain what the lower tiers can do? Choose two.
- 383. A manager asks where organisation-level security requirements are recorded, and where such requirements may originate. Which answer is correct?
- 384. Which four things does a plan of action and milestones do for security weaknesses found in programmes and systems?
- 385. Which two patterns in a plan of action and milestones does NIST identify as signs of a healthy process? Choose two.
- 386. Which two properties does NIST require of good security measures? Choose two.
- 387. A team collects security measurement data already summarised by business unit. Which practice does NIST recommend instead, and why?
- 388. An organisation operates a change board that reviews cost and schedule but has no security participant. Which NIST expectation is not met?
- 389. A team deploys vendor patches straight to production on the vendor's assurance that they are safe. Which NIST expectation does this skip?
- 390. Which observable trend does NIST offer as evidence that configuration management is working?
- 391. Which two uses does NIST identify for incident statistics in managing a security programme? Choose two.
- 392. Network monitoring data is reviewed in isolation by the operations team. Which improvement does NIST recommend?
- 393. Which four things does continuous assessment do after a system's initial authorisation?
- 394. A manager must explain to the training team the difference between awareness and training as NIST defines them. Which statement is correct?
- 395. Awareness material is criticised for not explaining how to configure a control. How does NIST define the scope of awareness content?
- 396. Which sequence correctly describes the NIST learning continuum, with certification's place in it?
- 397. An employee disputes a sanction on the ground that they were never told the rule existed. Which role of awareness does NIST identify that this case illustrates?
- 398. Which two things does NIST say an awareness communications plan identifies? Choose two.
- 399. A candidate presents a certificate showing they attended a five-day course. What does NIST say such a certificate establishes?
- 400. Which sequence correctly describes the three major steps of developing an awareness and training programme?
- 401. An organisation buys a generic off-the-shelf awareness course and reports poor engagement. Which design principle does NIST identify?
- 402. Material developers ask what question should guide them. Which pairing does NIST give for awareness and for training respectively?
- 403. Which two groups does NIST include in the audience for awareness, beyond permanent employees? Choose two.
- 404. An awareness session is written to be usable by any organisation in any sector. Which risk does NIST attach to that approach?
- 405. Which two items does NIST say must be complete before implementation of an awareness and training programme begins? Choose two.
- 406. Business unit managers are surprised to receive a charge for the new awareness programme. Which implementation step did NIST expect?
- 407. Which two changes does NIST name as making an awareness and training programme obsolete if unattended? Choose two.
- 408. Which two data items does NIST say an automated awareness and training tracking system should capture? Choose two.
- 409. Tracking shows a gap between recorded training status and the organisation's standard. Which three follow-up actions does NIST name?
- 410. A feedback form asks only whether attendees enjoyed the session. Which two dimensions does NIST say a feedback strategy should also address? Choose two.
- 411. Which behaviour does NIST list as an indicator that an awareness programme is genuinely supported?
- 412. Which two metrics does NIST offer as evidence of improving workforce security performance? Choose two.
- 413. Which two of the four interdependent components of a security performance measurement programme does NIST name? Choose two.
- 414. An organisation with no documented procedures struggles to produce meaningful security metrics. Which explanation does NIST give?
- 415. Why does NIST place senior management support as the foundation of a security metrics programme rather than as one contributor among many?
- 416. NIST groups security metrics by the three questions they answer. Which set is correct?
- 417. A programme manager reports the percentage of systems that have been authorised. Which type of metric is this?
- 418. A manager measures the elapsed time between a major system change and the system's renewed authorisation. Which type of metric is this?
- 419. Why does NIST describe mission impact metrics as the hardest to generate?
- 420. An immature security programme attempts to report mission impact metrics and finds it cannot. Which explanation does NIST give?
- 421. NIST describes evidence in a metrics programme evolving through four stages. Which sequence is correct?
- 422. Which two attributes does NIST require of a metric chosen for initial implementation? Choose two.
- 423. A manager measures a process that does not yet exist. What does NIST say about the result?
- 424. Which two items does NIST say must be documented alongside each metric? Choose two.
- 425. An organisation assigns weights to its security metrics. On what does NIST say those weights should be based?
- 426. A metric shows that only a third of security plans are approved, but nobody can say why. Which remedy does NIST describe?
- 427. Which two causes of poor control performance does NIST name that a purely technical investigation would miss? Choose two.
- 428. Which three activities does NIST include in analysing security measurement data?
- 429. Which two corrective actions does NIST name in response to a measured performance gap? Choose two.
- 430. NIST orders candidate corrective actions before selecting among them. Which ordering does it prescribe?
- 431. Having prioritised a list of corrective actions, how many does NIST suggest taking forward for full cost-benefit analysis?
- 432. Which benefit does NIST attribute to measuring performance frequently rather than annually?
- 433. Which two things does NIST say a metrics implementation plan should establish? Choose two.
- 434. A manager assumes metrics can only justify additional spending. Which further use does NIST identify?
- 435. Which two existing data sources does NIST say security metrics can be derived from? Choose two.
- 436. NIST identifies people as arguably the weakest element in securing systems. Which controls does it name as those that address the risk people introduce?
- 437. Which two items does NIST expect enterprise-level policy to cover for the awareness and training programme? Choose two.
- 438. Which sequence correctly describes NIST's six-step continuous monitoring process?
- 439. A monitoring programme collects large volumes of data but has no defined process for acting on it. How does NIST weigh these two aspects?
- 440. Which two things must a continuous monitoring strategy maintain, according to SP 800-137? Choose two.
- 441. Which two things does establishing a continuous monitoring programme settle, under SP 800-137? Choose two.
- 442. Monitoring produces a finding that a control is ineffective. Which two categories of response does SP 800-137 permit? Choose two.
- 443. How does SP 800-137 contrast an initial authorisation with continuous monitoring?
- 444. An organisation proposes assessing every aspect of every control continuously. What does SP 800-137 say?
- 445. In which circumstance does SP 800-137 identify sampling of security objects as particularly efficient?
- 446. An organisation sets one monitoring frequency and applies it to every metric permanently. Which two points does SP 800-137 make? Choose two.
- 447. Which two events does SP 800-137 say should cause monitoring priorities to be adjusted? Choose two.
- 448. Which advantage does SP 800-137 attribute to automated monitoring tools over human analysts?
- 449. How does SP 800-137 describe the intended relationship between automation and security professionals?
- 450. A monitoring programme is built entirely around the data the organisation can already collect automatically. Which caution does SP 800-137 give?
- 451. An organisation deploys sophisticated monitoring technology but its staff routinely bypass the surrounding procedures. What does SP 800-137 say results?
- 452. Which two capabilities does SP 800-137 say to look for when selecting continuous monitoring tools? Choose two.
- 453. An organisation is deciding how far to automate its monitoring. Which two considerations does SP 800-137 raise? Choose two.
- 454. Which two continuous monitoring responsibilities does SP 800-137 assign to the risk executive function? Choose two.
- 455. Which two duties does SP 800-137 assign to the senior information security officer within continuous monitoring? Choose two.
- 456. Which two decisions does SP 800-137 assign to the authorising official in continuous monitoring? Choose two.
- 457. Which two continuous monitoring duties does SP 800-137 place with the system owner? Choose two.
- 458. Beyond monitoring the controls it provides, which further duty does SP 800-137 place on a common control provider?
- 459. In what order does SP 800-137 say the security control assessor produces and uses the security assessment plan?
- 460. A monitoring strategy states only that it will be reviewed annually. Which further element does SP 800-137 require?
- 461. Which two things is a monitoring strategy checked for when it is reviewed, under SP 800-137? Choose two.
- 462. Where does SP 800-137 say the organisation-wide monitoring strategy and its general implementation procedures are typically developed?
- 463. An organisation's monitoring strategy is drafted at the business process tier. What does SP 800-137 require before it takes effect?
- 464. Which two subjects does SP 800-137 say training for monitoring roles may cover? Choose two.
- 465. Which two constraints does SP 800-137 say may limit the decisions of officials at the upper tiers? Choose two.
- 466. Which two inputs shape a system-level continuous monitoring strategy, according to SP 800-137? Choose two.
- 467. Which three things does system-level continuous monitoring address under SP 800-137?
- 468. An organisation believes only an external firm can perform an independent control assessment. What does NIST actually require of assessor independence?
- 469. Which four things does monitoring at the system tier confirm about controls, under SP 800-137?
- 470. What role does SP 800-137 give to metrics and dashboards at the upper tiers of an organisation?
- 471. Which two documents does SP 800-137 say a well-run monitoring programme keeps current, rather than letting them age between authorisations? Choose two.
- 472. A supply chain programme sets itself the objective of eliminating supply chain risk. How does NIST frame the correct objective?
- 473. Which two factors does NIST say should determine how deep and mature a supply chain risk capability needs to be? Choose two.
- 474. Which two examples does NIST give of non-adversarial supply chain threats? Choose two.
- 475. NIST splits supply chain vulnerabilities into external and internal. Which pairing is correct?
- 476. Which two difficulties does NIST identify in dealing with supply chain vulnerabilities? Choose two.
- 477. A single cloud provider suffers a large-scale outage and several organisations in the same supply chain are disrupted at once. Which supply chain property does NIST use this to illustrate?
- 478. Which model does NIST recommend for distributing accountability in supply chain risk management?
- 479. An organisation forms a cross-functional supply chain risk team and disbands the risk responsibilities previously held within each discipline. What does NIST say about this?
- 480. Which two acquisition routes does NIST say supply chain risk must also be addressed for, beyond formal procurement? Choose two.
- 481. NIST identifies a critical first step in managing supply chain risk. What is it?
- 482. NIST recommends segmenting suppliers into groupings. What is the purpose of that segmentation?
- 483. Which two things does NIST say supplier inventory and mapping reveals? Choose two.
- 484. Which two acquisition practices does NIST name for managing supply chain risk? Choose two.
- 485. A project timeline allows no room for supplier security assessment before award. What does NIST say organisations should do?
- 486. A procurement for a security service is to be awarded on a lowest price technically acceptable basis. What does NIST advise?
- 487. Which two participants does NIST say must be on the acquisition team so the security view is present when requirements are set? Choose two.
- 488. Why does NIST place determination of criticality at the planning step of a procurement rather than later?
- 489. At which step of the procurement process does NIST place robust due diligence research producing a supplier risk profile?
- 490. A team treats its initial due diligence questionnaire as the complete picture of supplier risk. What warning does NIST give?
- 491. During market research an organisation finds only two viable suppliers exist worldwide for a needed component. How does NIST treat that observation?
- 492. Which two post-award changes does NIST say should be monitored because they alter supply chain risk exposure? Choose two.
- 493. A supplier's risk profile deteriorates beyond what any mitigation can bring back within tolerance. Which contractual provision does NIST say should exist?
- 494. An organisation assesses a supplier thoroughly at award and never again during a five-year contract. Which contract management practice does NIST expect?
- 495. A supplier suffers a disruption but does not report it, arguing it was not serious. Which contract provision does NIST say should have prevented the dispute?
- 496. Which two validation methods does NIST name for supplier assurance, and what governs how rigorous the choice should be? Choose two.
- 497. An organisation wants security requirements to be more than a post-award discussion with the winning bidder. Which mechanism does NIST describe?
- 498. Which two acquisition security techniques does NIST name for protecting against tampering and counterfeiting in transit? Choose two.
- 499. Which two supply chain risk activities does NIST map to the operate and maintain phase of the procurement process? Choose two.
- 500. Requirements are flowed down to subcontractors but nothing checks whether they are met. Which linkage does NIST require?
- 501. Which two benefits does NIST attribute to sharing supply chain risk information within a community? Choose two.
- 502. What does NIST ask suppliers to provide with products, including hardware that carries logic?
- 503. Which three things does a security learning programme strategic plan set out, according to NIST?
- 504. A learning programme manager struggles to justify the programme to executives. Which linkage does NIST say demonstrates why it is needed?
- 505. At what point in the funding process does NIST expect the learning programme strategy to be reviewed and agreed?
- 506. Which two workforce groups does NIST specifically say a learning plan should provide for? Choose two.
- 507. An organisation with an existing learning programme wants to reshape it. Which analysis does NIST recommend first?
- 508. NIST separates policy from procedure by function. Which pairing is correct?
- 509. Which two benefits does NIST attribute to establishing learning programme policies and procedures? Choose two.
- 510. Which policy pattern does NIST describe for enforcing awareness training completion?
- 511. When does NIST's example policy require role-based training for staff with significant security responsibilities?
- 512. An organisation allows exceptions to its training requirement but does not say who may grant them. Which element does NIST's example policy include?
- 513. Which acronym does NIST recommend as the test for a learning programme's goals, and what does it stand for?
- 514. A learning programme sets a goal of reducing susceptibility to social engineering and runs a phishing exercise in support. Which element of the strategy model is the exercise?
- 515. A review finds several learning activities that cannot be traced to any stated objective or goal. What does NIST say about such activities?
- 516. An organisation measures its learning programme purely by regulatory completion rates. Which three further effects does NIST say must also be measured?
- 517. Why does NIST treat training records as carrying heightened sensitivity?
- 518. Which risks does NIST ask a learning programme manager to identify and manage, beyond the risks the programme teaches about?
- 519. NIST distinguishes a learning goal from a learning objective. Which pairing is correct?
- 520. What distinguishes a learning outcome from a learning goal in NIST's terms?
- 521. A programme tests learners immediately after a course and reports high scores. Which additional measurement does NIST recommend, and what does it show?
- 522. Which two longitudinal behaviours does NIST offer as evidence of a learning programme's impact? Choose two.
- 523. Which measurement does NIST say demonstrates that staff can actually recognise and report a potential security event, which completion rates cannot show?
- 524. Which two organisational changes following technical training does NIST offer as measurements? Choose two.
- 525. What did NIST's research find about the learning metrics organisations actually use?
- 526. NIST divides the learning audience into three overlapping segments. Which set is correct?
- 527. Why does NIST say privileged access account holders receive training beyond the all-user programme?
- 528. How does NIST describe the relationship between privileged access holders and those with significant security responsibilities?
- 529. Which learning duty does NIST assign to managers in relation to staff with significant security responsibilities?
- 530. An employee completes the general awareness module but does not know the specific rules governing the application they use daily. Which managerial duty does NIST identify?
- 531. Which two responsibilities does NIST assign to an ordinary system user? Choose two.
- 532. Which sequence correctly describes the six phases of the security services life cycle?
- 533. Which three activities does NIST place in the initiation phase of the security services life cycle?
- 534. An organisation is about to choose a security service provider without knowing what its current environment costs or achieves. Which life cycle phase has been skipped?
- 535. Which three outputs does the solution phase of the security services life cycle produce?
- 536. A service has gone live and the organisation considers the engagement complete. What does NIST say the operations phase requires?
- 537. Which two activities does NIST place in the closeout phase of the security services life cycle? Choose two.
- 538. Why does NIST ask programme managers to identify the triggers for a replacement security service in advance?
- 539. Which two management tools does NIST name for making a security service provider accountable for results? Choose two.
- 540. NIST groups security services into three categories. Which set is correct?
- 541. Which two dependencies does NIST identify for operational security services? Choose two.
- 542. Two organisations run the same application but select different control mixes. Which two factors does NIST say determine the appropriate blend? Choose two.
- 543. Why might the same system warrant different controls in two different organisations, according to NIST?
- 544. A decision to outsource a security service is taken purely on cost. Which two consequences does NIST warn may follow? Choose two.
- 545. Which two of NIST's six issue categories for acquiring security services are correct? Choose two.
- 546. On funding decisions for security services, what does NIST say the focus should be?
- 547. An organisation engages an external security provider and finds long-established internal controls no longer make sense. How does NIST characterise this?
- 548. Which two questions does NIST include in provider evaluation about past performance? Choose two.
- 549. Which two commercial terms does NIST say to understand before signing with a security service provider? Choose two.
- 550. A provider's contingency planning policy is weaker than the organisation's own. Which question does NIST direct the organisation to ask?
- 551. Which two questions does NIST direct at a provider that will hold the organisation's data alongside other customers'? Choose two.
- 552. Which two personnel questions does NIST include in evaluating a security service provider? Choose two.
- 553. Which aspect of a provider's own position does NIST say should be evaluated as part of the strategic and mission questions?
- 554. Which two organisational considerations does NIST list before selecting a security product? Choose two.
- 555. Which two product considerations does NIST list for security product selection? Choose two.
- 556. Which two vendor considerations does NIST list for security product selection? Choose two.
- 557. Which selection preference does NIST express for security products where an evaluated option exists?
- 558. What does NIST say a cost-benefit analysis for security product selection should include, beyond the alternatives under consideration?
- 559. Which two roles does NIST include among those involved in selecting security products and services? Choose two.
- 560. An organisation begins a security service procurement by comparing vendors' offerings. Which prior step does NIST prescribe?
- 561. Which two delivery arrangements does NIST identify for a security service, beyond a commercial provider? Choose two.
- 562. What does NIST identify as the purpose of configuration management in security terms?
- 563. Which three kinds of change does NIST say the configuration management process covers?
- 564. Why does NIST require changes to be tested before implementation?
- 565. A manager argues a formal change process is not worth its overhead for a small organisation. Which economic argument does NIST make?
- 566. Which two things does the baseline configuration control require an organisation to maintain? Choose two.
- 567. A change log records that each change occurred but says nothing about its effect. Which control requirement is unmet?
- 568. What standard does the configuration settings control set for how security settings should be configured?
- 569. Which two elements does the least functionality control require? Choose two.
- 570. NIST notes that many system functions and services are provided by default. What does it ask organisations to do about them?
- 571. How does the access restrictions for change control differ from configuration change control?
- 572. Which two disciplines does NIST say configuration management interlocks with, beyond risk management? Choose two.
- 573. Why does NIST say the configuration management process can only begin after the initial control baseline is selected?
- 574. Which definition of security accreditation does NIST give?
- 575. A significant change is identified through the configuration management process. What does NIST say must follow?
- 576. Which principle does NIST say change management must address so that changes reach production only after being tested and approved?
- 577. Which two configuration management responsibilities does NIST assign to the system owner? Choose two.
- 578. Which two responsibilities does NIST assign to the configuration control review board? Choose two.
- 579. Which two daily configuration management duties does NIST assign to the configuration manager? Choose two.
- 580. What is the information systems security officer's role in relation to the configuration control board?
- 581. NIST assigns system users a defined role in configuration management. What is it?
- 582. Which two sources of change initiation does NIST identify beyond users and system owners? Choose two.
- 583. Which two questions does NIST's impact analysis of a change request ask? Choose two.
- 584. Which three decisions can conclude a change request under NIST's process?
- 585. Which staffing arrangement does NIST recommend for moving an approved change into production, and why?
- 586. Which two checks does NIST describe under continuous monitoring within the configuration management process? Choose two.
- 587. Which three steps does NIST describe for patch management within the configuration process?
- 588. How many steps does the Risk Management Framework have, and what distinguishes the first?
- 589. What does categorising a system determine, and what does that determination drive?
- 590. An organisation plans to select the baseline first and tailor it as a separate later exercise. How does the RMF define the Select step?
- 591. Which three things does the RMF Assess step determine about controls?
- 592. What determination does the RMF Authorize step make, and what can it cover?
- 593. Which two activities does the RMF Monitor step include beyond assessing control effectiveness? Choose two.
- 594. An organisation with an agile delivery model wants to iterate between RMF steps rather than run them once in order. What does SP 800-37 permit?
- 595. How does SP 800-37 balance the obligation to perform RMF tasks against organisational flexibility?
- 596. A team wants to select, tailor, implement and assess controls progressively as a system is built rather than in a single pass. Is this permitted?
- 597. Which two things does SP 800-37 require before an organisation re-enters the RMF at a chosen step? Choose two.
- 598. Which three designations does NIST use for controls, and what governs the designation?
- 599. Why does SP 800-37 require traceability from each control back to the requirement it satisfies?
- 600. Which two organisation-level RMF Prepare tasks does SP 800-37 name? Choose two.
- 601. Why does SP 800-37 require common controls to be identified, documented and published?
- 602. Which two sources does an organisation-level risk assessment draw on, under SP 800-37? Choose two.
- 603. Which architectural question does SP 800-37 give as an example for an organisation-level risk assessment?
- 604. Why does SP 800-37 ask risk assessment to account for variability across an organisation?
- 605. Which two things does a system security plan contain, according to NIST?
- 606. How does NIST characterise system security plans, and what accompanies them for controls not yet in place?
- 607. An organisation produces its system security plan as an output of the authorisation process. What sequence does NIST require?
- 608. A small organisation assigns one individual to several security planning roles. Which caution does NIST give?
- 609. Which two decisions does NIST assign to the information owner? Choose two.
- 610. An information owner shares data with a partner organisation and considers protection now the partner's responsibility. What does NIST say?
- 611. Which two responsibilities does NIST assign to the system owner in relation to the security plan? Choose two.
- 612. Which two things do rules of behaviour do, according to NIST? Choose two.
- 613. How does NIST require a user's acceptance of the rules of behaviour to be recorded?
- 614. Why does NIST say the acknowledgement of the rules of behaviour matters as much as the text itself?
- 615. Which two topics does NIST list as typically covered by rules of behaviour? Choose two.
- 616. A drafter proposes to reproduce the entire security policy inside the rules of behaviour. What does NIST advise instead?
- 617. Who approves a system security plan before authorisation, and what makes that approval meaningful?
- 618. Why must a system and its information be categorised before the security plan is written?
- 619. Which two statements about defining a system's security boundary are correct under NIST guidance? Choose two.
- 620. How does NIST define a subsystem?
- 621. Which two activities does NIST include in tailoring a control baseline? Choose two.
- 622. An organisation tailors its control baseline but records only the final control set. Which requirement is unmet?
- 623. Which two local conditions does NIST say may be used to tailor a control baseline? Choose two.
- 624. How does NIST define a compensating security control?
- 625. Which two of the three conditions governing the use of a compensating control does NIST state? Choose two.
- 626. A system team decides to substitute a compensating control and records it in their own change log only. Which requirement is unmet?
- 627. Which two scopes can a common control cover, according to NIST? Choose two.
- 628. To whom does NIST say responsibility for developing, implementing and assessing a common control should be assigned?
- 629. Which efficiency does NIST attribute to the common control approach?
- 630. What risk does NIST identify as arising from widespread dependence on common controls?
- 631. How does NIST recommend common controls be handled across many system security plans?
- 632. Which two organisational conditions does NIST say make identification of common controls work? Choose two.
- 633. What does scoping guidance provide, and what must the security plan record about its use?
- 634. Who must review and approve the application of scoping guidance to a system's controls?
- 635. Which two roles does NIST say must be involved in security categorisation, showing it is not a single team's task? Choose two.
- 636. On what basis is a system rated low, moderate or high against each security objective?
- 637. How does NIST define adequate security?
- 638. A minor application runs inside a larger general support system. What does NIST say about its security plan?
- 639. Which security planning duty does NIST assign to the chief information officer regarding controls the organisation offers for inheritance?
- 640. Which coordination duty does NIST assign to the senior information security officer in security planning?
- 641. How does NIST define a system interconnection?
- 642. Which two levels of system interconnection does NIST describe? Choose two.
- 643. Which specific risk does NIST identify when two systems are interconnected?
- 644. What does NIST require before an organisation connects its system to another system?
- 645. Which two things does a formal interconnection agreement specify, according to NIST? Choose two.
- 646. Why does NIST require each interconnected system's controls to be evaluated against the other's requirements?
- 647. Which two purposes does NIST give for maintaining clear lines of communication between interconnected parties? Choose two.
- 648. How often does NIST say the security controls on an interconnection should be reviewed?
- 649. Two systems with different configurations and control sets are to be interconnected. Why does NIST say the resulting risk must be weighed carefully?
- 650. Which four phases make up the life cycle management approach for interconnecting systems?
- 651. Which two participants does NIST include in a joint planning team for an interconnection? Choose two.
- 652. Which three factors does NIST say the business case for an interconnection should weigh?
- 653. Why does NIST say each party should consider reauthorising its system before establishing an interconnection?
- 654. Which two items does NIST say an interconnection security agreement contains, beyond the technical and security requirements? Choose two.
- 655. Which two matters does a memorandum of understanding for an interconnection settle, according to NIST? Choose two.
- 656. Who must sign the memorandum of understanding for an interconnection, and why does it matter?
- 657. Why does NIST say interconnection agreements themselves need protection?
- 658. Which three outcomes are available to an authorising official reviewing a proposed interconnection?
- 659. Under what condition does NIST permit the two interconnection documents to be combined, and what must be preserved?
- 660. Which two items does NIST say an interconnection implementation plan must identify? Choose two.
- 661. Which two things does NIST say both parties should examine closely when a new interconnection is activated? Choose two.
- 662. Which two activities does NIST include in maintaining an established interconnection? Choose two.
- 663. Which three things does NIST say a written notice of planned disconnection should describe?
- 664. Which two considerations govern the scheduling of a planned disconnection, according to NIST? Choose two.
- 665. What must both organisations agree about shared data when an interconnection is disconnected?
- 666. Which two conditions does NIST attach to an emergency disconnection performed without written notice? Choose two.
- 667. Which two things does NIST require after an emergency disconnection? Choose two.
- 668. An interconnection was terminated because of an attack and both parties now wish to restore it. Which two steps does NIST require first? Choose two.
- 669. An interconnection has been down for more than ninety days and the parties want to restore it. What does NIST require?
- 670. How does NIST relate assessment to measurement in SP 800-55?
- 671. Which two kinds of assessment does NIST name alongside risk assessment when evaluating security risk? Choose two.
- 672. How does NIST characterise the relationship between programme assessments, control assessments and risk assessment?
- 673. Which tension does NIST identify in choosing how many security measures to collect?
- 674. Which three methods does NIST name for collecting security data?
- 675. NIST describes a simulated phishing test as an example of which data collection method?
- 676. What distinguishes observational data in NIST's account of measurement?
- 677. Which sampling method gives every item an equal chance of selection, aiming for an unbiased picture?
- 678. Which two characteristics does NIST attribute to stratified sampling? Choose two.
- 679. Which weakness does NIST identify in systematic sampling?
- 680. How does NIST characterise a qualitative assessment in SP 800-55?
- 681. An organisation reports that it is at level three on a maturity model. How does NIST classify that number?
- 682. Which example does NIST give of a quantitative assessment whose values keep their meaning outside the assessment?
- 683. Which results does NIST count as measures for the purposes of SP 800-55?
- 684. Which two limitations does NIST attach to qualitative assessment, despite its ease of use? Choose two.
- 685. Why does NIST say an organisation should consider its motivations before choosing between quantitative and qualitative assessment?
- 686. Which measure does NIST say gives sharper insight into patching performance, and why?
- 687. An organisation early in its measurement journey relies on a risk matrix. What progression does NIST describe?
- 688. Which three properties does NIST require of meaningful security measures?
- 689. How does NIST say measurement strengthens governance?
- 690. Which pairing correctly matches metric level to the kind of decision it supports?
- 691. Which two characteristics does NIST require of a meaningful metric? Choose two.
- 692. What consequence does NIST attribute to poorly chosen quantitative metrics?
- 693. Which test does NIST give for deciding whether to keep a quantitative metric?
- 694. Why does NIST emphasise keeping metrics consistent over time?
- 695. How does NIST relate key risk indicators and key performance indicators to metrics generally?
- 696. For evaluating cybersecurity awareness training, which approach does NIST prefer?
- 697. Which two conditions does NIST say organisation-level measurement requires? Choose two.
- 698. NIST states that security cannot be measured perfectly. Which reason does it give, and what does it advise instead?
- 699. An organisation trained on the earlier NIST incident response guidance is updating to Revision 3. What structural change must it explain to staff?
- 700. Which set correctly names the phases of the older SP 800-61 incident response life cycle?
- 701. Which two changes in the incident landscape did NIST cite to justify revising its incident response model? Choose two.
- 702. In the SP 800-61r3 model, which three CSF functions constitute incident response itself, as distinct from preparation?
- 703. An incident is still in recovery and a responder has identified a clear lesson. What does the current NIST guidance advise?
- 704. In NIST's mapping of the old model to CSF functions, what does the former detection and analysis phase correspond to?
- 705. The former containment, eradication and recovery phase maps onto which CSF functions, and what does that mapping reflect?
- 706. Where do lessons from all six CSF functions go in the SP 800-61r3 model, and what happens to them?
- 707. Does NIST mandate its own incident response life cycle model, and which organisations does it say benefit most from one stressing continuous improvement?
- 708. Which two decisions does NIST place with the organisation's leadership team during incident response? Choose two.
- 709. Which two duties does NIST assign to incident handlers? Choose two.
- 710. Which two sourcing arrangements does NIST recognise for incident handlers, beyond permanent staff? Choose two.
- 711. A large organisation operates several incident response teams by geographic segment. What does NIST advise?
- 712. Which two review roles does NIST assign to legal experts in incident response? Choose two.
- 713. Why does NIST say a media engagement strategy must be prepared in advance?
- 714. Which two ways does NIST say human resources is an incident response stakeholder? Choose two.
- 715. Which two reasons does NIST give for including physical security in incident response? Choose two.
- 716. Which two contributions do asset owners make during incident response, according to NIST? Choose two.
- 717. An organisation contracts a provider to perform incident detection and response. Which two things does NIST say the contract must define? Choose two.
- 718. Which two restrictions does NIST say an incident response provider contract should state? Choose two.
- 719. Which two advantages does NIST attribute to a service provider in detecting malicious activity? Choose two.
- 720. Which risk does NIST attach to engaging an incident response provider, and which deterrent does it name?
- 721. Which two elements does NIST say most incident response policies open with? Choose two.
- 722. Which two things does an incident response policy define, according to NIST? Choose two.
- 723. Which two further elements does NIST include in an incident response policy? Choose two.
- 724. How does NIST order policy, plan and procedures for incident response?
- 725. Since detailed procedures cannot cover every situation, which two kinds does NIST advise documenting? Choose two.
- 726. Which two purposes does NIST say periodic exercising of procedures serves? Choose two.
- 727. How does NIST characterise a playbook in relation to procedures?
- 728. How is SP 800-61r3 structured in relation to CSF 2.0?
- 729. In the incident response Community Profile, what does a priority of medium indicate about a CSF outcome?
- 730. In the incident response Community Profile, which tags distinguish an obligation from something to be weighed?
- 731. A recommendation appears against a CSF category rather than a specific subcategory. How does the Community Profile treat it?
- 732. Which Govern category does the incident response Community Profile rate as high priority, and on what basis?
- 733. Which three legal aspects does the Community Profile ask cybersecurity requirements to capture?
- 734. Which two kinds of dependency knowledge does the Community Profile say aid prioritisation of response and recovery? Choose two.
- 735. The Community Profile asks that incident decision-making be informed by more than cybersecurity risk. Which two other risk types does it name? Choose two.
- 736. Which two uses does the Community Profile identify for a standardised risk calculation method during incident response? Choose two.
- 737. Which two recommendations does the Community Profile make about incident response roles? Choose two.
- 738. What does the Community Profile recommend be taken into account when the organisation adjusts its cybersecurity risk management strategy?
- 739. Which two ways do asset inventories help incident responders, according to the Community Profile? Choose two.
- 740. Which three uses does the Community Profile give for automatically updated hardware and software inventories?
- 741. Why does the Community Profile recommend maintaining representations of authorised network data flows?
- 742. Which three attributes does the Community Profile say make data inventories most valuable to responders?
- 743. Which three forms does NIST say an evaluation of the incident response programme can take?
- 744. Which two things does a lessons-learned meeting held as recovery concludes achieve, according to NIST? Choose two.
- 745. Which two places can an improvement identified during incident response apply to, according to NIST? Choose two.
- 746. Which three plan types does NIST identify as relevant to incident response?
- 747. Why does NIST require business continuity plans to be synchronised with incident response plans?
- 748. Which five characteristics does NIST say each cybersecurity plan should be built around?
- 749. What does NIST say a cybersecurity plan must identify for it to be considered complete?
- 750. Which two contributions does NIST say business continuity planners can make to incident response? Choose two.
- 751. Which two benefits does NIST attribute to reducing the number of incidents, beyond preventing the incidents themselves? Choose two.
- 752. Which detection advantage does NIST attribute to understanding the protection mechanisms already in place?
- 753. Why does the incident response Community Profile rate backups as high priority when most Protect outcomes are rated medium?
- 754. Which record does the Community Profile single out as preserving the information that detection, response and recovery depend on?
- 755. An organisation delivers role-based training covering technical skills but omitting what each role must do during an incident. Which recommendation is unmet?
- 756. Which two asset types does the Community Profile include in continuous monitoring for incident response that a purely network-focused programme would omit? Choose two.
- 757. A monitoring team tunes its detection rules until false positives fall to an acceptable level and considers the work done. Which half of NIST's recommendation is missing?
- 758. Which two things does the Community Profile say network monitoring should include beyond wired traffic? Choose two.
- 759. Which two things does the Community Profile say monitoring the physical environment should record? Choose two.
- 760. Which two things does the Community Profile include in monitoring personnel activity and technology usage? Choose two.
- 761. Which two aspects of external provider behaviour does the Community Profile say should be monitored? Choose two.
- 762. An endpoint is found to have missing patches and unauthorised software. Which handling does the Community Profile recommend?
- 763. Why does the Community Profile recommend monitoring configurations against security baselines?
- 764. Given the volume of potentially adverse events, what does NIST recommend organisations rely on?
- 765. Which trade-off does NIST identify about the timing of incident detection?
- 766. A monitoring tool flags an anomaly and an analyst opens an incident record immediately. Which caution does NIST give?
- 767. Which two tool categories does the Community Profile name for continuously monitoring log events for known malicious and suspicious activity? Choose two.
- 768. Some technologies in the estate cannot be adequately monitored through automation. What does NIST recommend?
- 769. Which practice does NIST identify as what makes event correlation practical across many sources?
- 770. Which practice does NIST suggest so that response work is tracked from the moment of detection?
- 771. Which three sources does the Community Profile name for acquiring vulnerability disclosures about the organisation's own technologies?
- 772. Which two inputs does NIST say the decision to declare an incident should weigh? Choose two.
- 773. A team handles incidents strictly in the order they are reported. What does NIST say about this practice?
- 774. Which activity does NIST describe as perhaps the most critical decision point in the whole incident response process?
- 775. Which two risk evaluation factors does NIST name for prioritising an incident? Choose two.
- 776. Which two items does NIST say incident tracking should record alongside a summary? Choose two.
- 777. Which arrangement does NIST suggest to give a single point of ownership for each incident?
- 778. Which two plans might executing the incident response plan require the organisation to activate as well? Choose two.
- 779. Which two things does a preliminary triage review establish, according to NIST?
- 780. Which two examples does NIST give of incidents reported to an organisation by outsiders? Choose two.
- 781. Which two incident types does NIST give as examples of categorisation, and when does categorisation occur?
- 782. Which four factors does NIST say set how quickly response should be performed for each incident?
- 783. Which trade-off does NIST identify in selecting a response strategy for an active incident?
- 784. NIST distinguishes escalation from elevation in incident response. Which pairing is correct?
- 785. Beyond the incident's characteristics, which factor does NIST say must be weighed in deciding when to begin recovery?
- 786. What does the Incident Analysis category focus on, in CSF terms?
- 787. With what does NIST say root cause analysis of an incident begins?
- 788. A response team identifies the immediate trigger of an incident and closes the analysis. Which NIST recommendation is unmet?
- 789. Which three means of recording facts and actions during an investigation does NIST name?
- 790. Which two kinds of sensitive material do incident response records commonly contain, according to NIST? Choose two.
- 791. Formal chain-of-custody handling is not applied to a malware incident. Does NIST regard the collected data as evidence?
- 792. Which two factors does NIST say the decision on evidence retention should weigh? Choose two.
- 793. Which aspect of incident response does NIST describe as often one of the most challenging?
- 794. Where does NIST say responders should search when estimating an incident's magnitude?
- 795. Which consequence does NIST attach to skipping or performing magnitude estimation superficially?
- 796. What does the Detect function encompass in the incident response Community Profile?
- 797. How does NIST define a vulnerability disclosure?
- 798. What does NIST recommend detection technologies do with the incidents they have confirmed?
- 799. NIST sorts incident response communication into four kinds. Which set is correct?
- 800. How does NIST distinguish incident notification from incident coordination?
- 801. When does NIST say the mechanisms for coordinating with affected parties should be established?
- 802. Which two things should established incident coordination procedures state? Choose two.
- 803. Which two characteristics of the organisation does NIST say determine which incident notification laws apply? Choose two.
- 804. Which two conditions govern notifying law enforcement or a regulator, under NIST guidance? Choose two.
- 805. Why does NIST describe voluntary incident information sharing as mutually beneficial?
- 806. How does NIST frame the economic effect of sharing detection techniques between organisations?
- 807. Which two characteristics does NIST attribute to incident handlers coordinating across organisations? Choose two.
- 808. Which specific reporting path does NIST identify for malicious insider activity?
- 809. How does NIST characterise the duty to inform senior leadership about a major incident?
- 810. Which two factors does NIST say containment criteria may weigh? Choose two.
- 811. A team proposes redirecting an attacker into a sandbox to gather more evidence. Which consultation does NIST require first?
- 812. Which danger does NIST attach to deliberately delaying containment in order to observe an attacker?
- 813. Which two purposes does containment serve, according to NIST? Choose two.
- 814. Which two automatic containment actions does NIST give as examples? Choose two.
- 815. Which example does NIST give of an incident type a third party might be authorised to contain automatically on the organisation's behalf?
- 816. An organisation deploys fully automated containment and removes the handlers' ability to intervene. Which NIST recommendation does this breach?
- 817. Which three eradication actions does NIST give as examples of eliminating persistence mechanisms and entry points?
- 818. Why does NIST require every affected host and service to be identified during eradication?
- 819. Which three things does NIST say personnel do during incident recovery?
- 820. Which two operations does NIST include in incident recovery? Choose two.
- 821. An intrusion involves a highly sophisticated actor whose full set of techniques is not known. How far does NIST accept recovery may have to go?
- 822. Which two activities does NIST include in executing an incident recovery plan? Choose two.
- 823. Which two things must everyone with recovery responsibilities be told, according to NIST? Choose two.
- 824. Which three attributes does NIST say the choice of recovery actions should take into account?
- 825. Which three things are restoration assets checked for before use, under NIST guidance?
- 826. Recovery validates that essential services are restored in the appropriate order. What does NIST's guidance imply about when that order is decided?
- 827. After systems are restored and users are back online, which further NIST recommendation applies?
- 828. Which two checks does NIST require before a restored asset is placed back into production? Choose two.
- 829. Which three things does an after-action report document, and when is it produced?
- 830. How does NIST relate recovery communication to the communication performed during response?
- 831. Which two recommendations does NIST make about communicating with suppliers during recovery? Choose two.
- 832. Which two things should a public update on incident recovery explain, according to NIST? Choose two.
- 833. Which published resource does SP 800-61r3 cite as worked examples of incident response playbooks?
- 834. An organisation's monitoring surfaces adverse events but nobody can say when one becomes an incident. Which CSF 2.0 prerequisite is missing?
- 835. Which two outcomes belong to the CSF 2.0 Incident Management category? Choose two.
- 836. Which two requirements does CSF 2.0 place on the records of actions taken during an incident investigation? Choose two.
- 837. Under which CSF 2.0 function do containment and eradication sit, and which category holds them?
- 838. Why does CSF 2.0 require the integrity of backups to be verified before they are used to restore?
- 839. Which two things does CSF 2.0 require when incident recovery ends? Choose two.
- 840. How does CSF 2.0 treat public updates during incident recovery?
- 841. Under which CSF 2.0 function does the upkeep of the incident response plan sit, and what does that placement reflect?
- 842. Which source of improvement does CSF 2.0 name that involves parties outside the organisation?
- 843. Which two CSF functions does NIST say should be kept ready at all times and invoked when an incident occurs, rather than running continuously?
- 844. Which CSF 2.0 supply chain outcome addresses the involvement of suppliers in incident work?
- 845. How does CSF 2.0 treat the estimation of an adverse event's impact and scope?
- 846. How does NIST distinguish continuity planning from contingency planning?
- 847. Which two scoping options does NIST allow for a business continuity plan? Choose two.
- 848. Why must the business continuity planner coordinate with system owners?
- 849. What does a continuity of operations plan restore, where, and for how long?
- 850. A minor disruption is handled without moving to an alternate site. Does the continuity of operations plan apply?
- 851. Which two elements does NIST list as standard in a continuity of operations plan? Choose two.
- 852. Which plan type does NIST say non-government organisations generally use to cover their mission and business processes?
- 853. Which two things does a crisis communications plan provide, according to NIST? Choose two.
- 854. Why must crisis communications procedures be shared with the continuity and business continuity planners?
- 855. Which two statements about a cyber incident response plan are correct under NIST's plan taxonomy? Choose two.
- 856. Which two characteristics define the scope of a disaster recovery plan under NIST's taxonomy? Choose two.
- 857. What relationship does NIST describe between a disaster recovery plan and system contingency plans?
- 858. What is the primary difference between an information system contingency plan and a disaster recovery plan?
- 859. Which sequence does NIST describe when a disaster forces relocation of several systems?
- 860. Which two items does an information system contingency plan carry, according to NIST? Choose two.
- 861. Which two features characterise an occupant emergency plan under NIST's taxonomy? Choose two.
- 862. When is an occupant emergency plan executed relative to the continuity and disaster recovery plans, and why?
- 863. Which statement about a crisis communications plan is correct under NIST's plan taxonomy?
- 864. An attack spreads beyond the systems the response team first contained. Which relationship does NIST describe?
- 865. Why does NIST insist the various contingency-related plans be coordinated during development and update?
- 866. Which sequence matches NIST's seven-step contingency planning process?
- 867. Where in the system life cycle does NIST place the contingency planning policy and the business impact analysis, and why there?
- 868. Which two things does a contingency planning policy statement establish, and what does NIST say it needs to succeed?
- 869. Which two items does NIST name as key elements of contingency planning policy? Choose two.
- 870. With which functions does NIST say contingency planning must be coordinated?
- 871. What does a business impact analysis do, in NIST's formulation?
- 872. Which two outputs does NIST say business impact analysis results feed? Choose two.
- 873. A system's design and components change substantially during acquisition. What does NIST expect of the business impact analysis done earlier?
- 874. An auditor finds the organisation's plan types do not match NIST's descriptions exactly. Which NIST statement bears on this?
- 875. During a continuity of operations activation, what does the business continuity plan cover in NIST's model?
- 876. What does maximum tolerable downtime represent?
- 877. Which definition matches recovery time objective as NIST states it?
- 878. Which quantity does recovery point objective express?
- 879. Why is recovery point objective not counted as part of maximum tolerable downtime, while recovery time objective is?
- 880. Why does NIST expect recovery time objective to be shorter than maximum tolerable downtime?
- 881. What does NIST say determining the recovery time objective allows planners to do?
- 882. The achievable recovery time objective exceeds a maximum tolerable downtime that cannot be relaxed. What does NIST direct?
- 883. What became of the term maximum allowable outage used in an earlier NIST contingency guide?
- 884. How does NIST describe the two cost curves that determine an optimal recovery solution?
- 885. Why can't one organisation adopt another's cost balance point for recovery investment?
- 886. Which four inputs does NIST say determine system resource recovery priorities, and where does that step sit?
- 887. Where an outage can be prevented feasibly and cost-effectively, which does NIST prefer?
- 888. How does NIST treat power provision among preventive contingency controls?
- 889. Which preventive contingency control does NIST specify with placement both above and below the computer room?
- 890. Which preventive contingency control does NIST name for protecting backup media and vital paper records?
- 891. On what does NIST say the minimum frequency and scope of backups should be based?
- 892. Which two items does NIST expect a backup policy to designate beyond frequency and scope? Choose two.
- 893. Which two criteria does NIST give for selecting an offsite storage facility? Choose two.
- 894. Beyond confirming data is stored correctly, which further backup-media test does NIST recommend?
- 895. An organisation leases space with power, telecommunications connections and environmental controls but no system hardware. Which alternate site type is this?
- 896. Which description matches a warm site under NIST's definitions?
- 897. Which two attributes distinguish a hot site from a warm site under NIST's definitions? Choose two.
- 898. Which alternate site type does NIST describe as a self-contained transportable shell fitted with the equipment a particular recovery requires?
- 899. Which two characteristics define a mirrored site under NIST's definitions? Choose two.
- 900. How does NIST characterise the cost and readiness extremes of the alternate site options?
- 901. On NIST's alternate-site comparison, which row matches a warm site?
- 902. A plan relies on a mobile site delivered within a day. Which caveat does NIST attach?
- 903. Which two considerations govern where a fixed alternate site is located, per NIST? Choose two.
- 904. Which three ownership models for alternate sites does NIST name?
- 905. What must be negotiated in advance with a commercial alternate site provider serving many customers?
- 906. Which two considerations does NIST attach to entering a reciprocal agreement? Choose two.
- 907. Which two checks does NIST specify when testing a reciprocal arrangement? Choose two.
- 908. Why does NIST want the alternate site agreement to state what constitutes a disaster and how notification occurs?
- 909. Which contractual detail does NIST say determines whether an alternate site's capacity will actually be available?
- 910. Which review does NIST require before an alternate site agreement is relied on?
- 911. Which two occupancy terms does NIST expect an alternate site agreement to fix? Choose two.
- 912. Which three equipment replacement strategies does NIST name?
- 913. Which two provisions does NIST expect in a service level agreement for emergency equipment? Choose two.
- 914. When a catastrophe affects many of a vendor's clients at once, which organisations commonly receive the highest replacement priority?
- 915. Which trade-off does NIST describe between buying replacement equipment on demand and storing it in advance?
- 916. Which risk does NIST attach to a replacement strategy that depends on shipment after a catastrophic disaster?
- 917. Which two less obvious costs does NIST say a contingency budget must cover? Choose two.
- 918. Which role does NIST say a recovery strategy must include, and what decision rests with it?
- 919. Which three things must recovery team members understand, under NIST guidance?
- 920. Which two recovery technologies does NIST name alongside redundant arrays of independent disks? Choose two.
- 921. Which strategy does NIST pair with a moderate availability impact level?
- 922. Which systems must have a strategy for operating at an alternate facility for an extended period, under NIST guidance?
- 923. Which two external points of contact should a business impact analysis draw on? Choose two.
- 924. Which check does NIST require when evaluating whether an alternate site is adequate?
- 925. What distinguishes a test from other plan validation activities in NIST's usage?
- 926. Which two elements does NIST expect a contingency test to exercise? Choose two.
- 927. Without which two elements does NIST say a contingency test plan cannot show the plan is effective? Choose two.
- 928. Which scenario does NIST accept for a contingency test, and what quality does it require of it?
- 929. How does NIST distinguish contingency training from awareness?
- 930. Which training goal does NIST set for recovery personnel, and why?
- 931. Which two timing requirements does NIST set for contingency training? Choose two.
- 932. Beyond individual duties, which topic does NIST expect contingency training to cover?
- 933. Which description matches a tabletop exercise under NIST's usage?
- 934. What distinguishes a functional exercise from a tabletop exercise?
- 935. What separates an exercise from a test in NIST's terminology?
- 936. How does NIST characterise the way exercises are driven?
- 937. Which exercise rigour does NIST match to a moderate-impact system?
- 938. What must a full-scale functional exercise for a high-impact system include?
- 939. Which two things does NIST require of every test and exercise?
- 940. How do the results of a training, test or exercise event reach the plan, per NIST?
- 941. When does NIST say exercises and tests should be run?
- 942. To which organisational process does NIST tie contingency plan maintenance?
- 943. Which plan element does NIST single out as needing review more often than the plan as a whole?
- 944. Where does NIST say a copy of the contingency plan should be kept, and why?
- 945. Why does NIST require the distribution of a contingency plan to be marked and controlled, with a record of holders?
- 946. How does NIST recommend strict version control of the contingency plan be maintained?
- 947. Which material does NIST say should be stored with the contingency plan?
- 948. What does the record of changes in a contingency plan capture?
- 949. Which three phases structure an information system contingency plan under NIST?
- 950. Which criterion does NIST include among the bases for activating a contingency plan?
- 951. How many people does NIST say should hold the authority to activate the contingency plan?
- 952. Which range must notification procedures cover, per NIST?
- 953. Which operational benefit does NIST attribute to prompt notification of an impending disruption?
- 954. Why does NIST caution against relying on email for contingency notification?
- 955. Which detail must a call tree record beyond the assignment of notification duties?
- 956. Which content does NIST say a notification message may carry?
- 957. Why does NIST expect external organisations and interconnected system partners to be notified?
- 958. Which priority does NIST place above the speed of outage assessment?
- 959. Which element belongs in an outage assessment under NIST guidance?
- 960. What does NIST say may happen to notifications once outage assessment reveals the true impact?
- 961. What governs the sequence in which resources are recovered?
- 962. Which example does NIST give of the logical, as opposed to merely prioritised, ordering of recovery?
- 963. Which conditions should trigger escalation steps written into recovery procedures?
- 964. Which step does NIST include in typical recovery procedures before hardware installation begins?
- 965. Which documentation format does NIST recommend for recovery procedures, and why?
- 966. What may be running at the end of the recovery phase, under NIST's model?
- 967. Which two major activities make up the reconstitution phase?
- 968. What is concurrent processing in NIST's reconstitution guidance?
- 969. Which validation does NIST require to confirm files and databases are complete and current to the last backup?
- 970. Which judgement does NIST require after reconstitution?
- 971. Which activities does NIST include in deactivating the contingency plan?
- 972. Which further work can fall inside the reconstitution phase when the original facility is unrecoverable?
- 973. What must escalation procedures define, per NIST's recovery guidance?
- 974. Which three elements does NIST say a test, training and exercise programme needs to be repeatable rather than ad hoc?
- 975. How does NIST separate the plan coordinator's role from the exercise programme coordinator's?
- 976. Which four phases make up NIST's exercise event methodology, used for every event type?
- 977. Which activities belong to the design phase of an exercise, per NIST?
- 978. Which two subjects does the evaluation phase draw lessons for?
- 979. What ordering does NIST set between training sessions and exercises?
- 980. Which by-product does NIST attribute to running a training session?
- 981. How long does NIST say a tabletop exercise usually runs?
- 982. What does NIST say tabletop exercises are cost-effective tools for?
- 983. Which question does NIST put before scheduling a tabletop exercise?
- 984. Which approval does NIST treat as an essential development step for an exercise?
- 985. How far ahead does NIST say design should begin for a large, complex tabletop exercise?
- 986. Which sequencing does NIST advise for exercising senior-level and operational-level teams?
- 987. How does NIST differentiate the duration and pitch of senior-level and operational-level tabletop exercises?
- 988. What does NIST suggest accompany a tabletop exercise lasting more than four hours?
- 989. Which three standing objectives does NIST give a tabletop exercise?
- 990. Which two staff roles does a tabletop exercise require, and what must both know?
- 991. What does NIST have the facilitator and data collector do before a tabletop exercise?
- 992. How does NIST define a tabletop exercise scenario?
- 993. What does the facilitator guide contain for a tabletop exercise?
- 994. How does the participant guide differ from the facilitator guide?
- 995. Which misconception about exercise scenarios does NIST correct?
- 996. When must evaluation criteria for an exercise be written, and why?
- 997. How should exercise questions differ between senior and operational participants?
- 998. Why does NIST suggest seating participants away from their own teammates during a tabletop exercise?
- 999. Which facilitator skill does NIST call for when discussion drifts into the scenario's detail?
- 1000. Which three questions does the debrief immediately after a tabletop exercise put to participants?