- Home
- All questions
- Security program
CISM study material: Security program
379 questions of the 1000 in the CISM — Certified Information Security Manager quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 46. An assessment repeatedly finds the same deficiencies year after year, with no record of what was done about earlier findings. Which senior security officer responsibility is not being discharged?
- 50. Two employees commit the same policy violation, and one is dismissed while the other receives no sanction. Which role owns the practice that failed here?
- 52. A procurement completes without any security requirements in the contract, and the security office learns of it only at go-live. Which governance relationship failed?
- 60. A manager sets up ongoing monitoring of the security programme itself. Which two questions does NIST say that monitoring should answer? Choose two.
- 66. Monitoring consistently shows that one control family underperforms, but funding allocations the following year are unchanged. Which governance practice is not working?
- 80. A manager must explain what an authorisation boundary determines. Which answer is correct?
- 86. An organisation is preparing to rely on an external service provider. Which two things does SP 800-39 say it must establish? Choose two.
- 91. A project plans to gather functional requirements first and add security requirements once the design is stable. Why does SP 800-39 object?
- 93. A system cannot achieve the level of trustworthiness needed from its technical controls alone. What does SP 800-39 say the organisation should do?
- 96. A manager is aligning security activities to the system development life cycle. Which sequence of phases does NIST describe?
- 97. A programme treats its life cycle as strictly one-directional, refusing to revisit earlier phases. What does NIST say about this?
- 98. Servers are being retired and sent for disposal. Which two actions does SP 800-39 expect at this life cycle phase? Choose two.
- 99. A system is about to go live and the project manager proposes assessing control effectiveness after six months of operation. Why does SP 800-39 place that assessment earlier?
- 103. A programme discovers cost overruns only at delivery. Which investment phase and mechanism was intended to catch them earlier?
- 104. Security drivers differ across the investment life cycle. Which two pairings are correct? Choose two.
- 105. An organisation begins the seven-step process for integrating security into capital planning. What is the first step?
- 108. A security manager wants weaknesses found during assessment to actually attract funding. Which mechanism does NIST describe for connecting the two?
- 170. During design, an assessment shows a proposed component carries known weaknesses that a comparable alternative does not. What does SP 800-39 identify as the advantage of switching at this point?
- 223. Which two authorisation decisions can risk assessment results support, according to SP 800-30? Choose two.
- 238. An organisation maps only the risks its suppliers pose to it. Which point does SP 800-39 make about external risk relationships?
- 242. An organisation approves exceptions to policy in a change ticket and takes no further action. Which CSF 2.0 expectation is not being met?
- 243. A supplier's hardware is verified for authenticity and integrity only after it has been racked and connected. Which CSF 2.0 outcome does this fail?
- 245. An organisation applies the same assurance questionnaire to every one of its 900 suppliers and cannot complete the programme. Which CSF 2.0 outcome would address this?
- 246. A supplier is onboarded and the first security review takes place six months into the contract. Which CSF 2.0 outcome does this arrangement miss?
- 247. A supplier contract ends and the supplier retains administrative access and copies of organisational data for months afterwards. Which CSF 2.0 outcome addresses this?
- 263. IR 8286 warns two kinds of control must not be confused. Which pairing describes them correctly?
- 272. An organisation cannot say with confidence which devices it operates or where its data resides. What consequence does IR 8286 draw?
- 324. A mitigation cannot be implemented immediately because the necessary resources are unavailable. Which two things does IR 8286 say the corrective action plan records? Choose two.
- 346. How does SP 800-30 describe the role of security categorisation within risk assessment?
- 362. Which organisation-tier vulnerability does SP 800-30 illustrate with the example of subverted components entering the estate?
- 373. An organisation maintains a single combined asset list. Which two further inventories does CSF 2.0 expect to be maintained separately? Choose two.
- 374. A team ranks assets purely by replacement cost. Which basis does CSF 2.0 prescribe for prioritising assets?
- 375. An access review confirms permissions are enforced technically but finds no policy defining them and no periodic review. Which two elements of the CSF 2.0 outcome are missing? Choose two.
- 376. An organisation delivers one annual awareness module to everyone including its security engineers and developers. Which CSF 2.0 expectation is unmet?
- 377. A data protection programme addresses data at rest and data in transit. Which two further outcomes does CSF 2.0 name under Data Security? Choose two.
- 378. An organisation adopts a secure development standard and considers the outcome achieved. Which further expectation does CSF 2.0 attach?
- 379. Security expectations are communicated to suppliers verbally at kickoff meetings and recorded in no agreement. Which CSF 2.0 outcome does this fail?
- 380. An organisation monitors its own networks and endpoints continuously but performs no monitoring of the managed service provider operating part of its estate. Which CSF 2.0 outcome is missing?
- 381. Which pairing correctly describes a common control and a common control provider in NIST usage?
- 382. Which two decisions taken at the organisation tier does SP 800-39 say constrain what the lower tiers can do? Choose two.
- 383. A manager asks where organisation-level security requirements are recorded, and where such requirements may originate. Which answer is correct?
- 384. Which four things does a plan of action and milestones do for security weaknesses found in programmes and systems?
- 385. Which two patterns in a plan of action and milestones does NIST identify as signs of a healthy process? Choose two.
- 386. Which two properties does NIST require of good security measures? Choose two.
- 387. A team collects security measurement data already summarised by business unit. Which practice does NIST recommend instead, and why?
- 388. An organisation operates a change board that reviews cost and schedule but has no security participant. Which NIST expectation is not met?
- 389. A team deploys vendor patches straight to production on the vendor's assurance that they are safe. Which NIST expectation does this skip?
- 390. Which observable trend does NIST offer as evidence that configuration management is working?
- 391. Which two uses does NIST identify for incident statistics in managing a security programme? Choose two.
- 392. Network monitoring data is reviewed in isolation by the operations team. Which improvement does NIST recommend?
- 393. Which four things does continuous assessment do after a system's initial authorisation?
- 394. A manager must explain to the training team the difference between awareness and training as NIST defines them. Which statement is correct?
- 395. Awareness material is criticised for not explaining how to configure a control. How does NIST define the scope of awareness content?
- 396. Which sequence correctly describes the NIST learning continuum, with certification's place in it?
- 397. An employee disputes a sanction on the ground that they were never told the rule existed. Which role of awareness does NIST identify that this case illustrates?
- 398. Which two things does NIST say an awareness communications plan identifies? Choose two.
- 399. A candidate presents a certificate showing they attended a five-day course. What does NIST say such a certificate establishes?
- 400. Which sequence correctly describes the three major steps of developing an awareness and training programme?
- 401. An organisation buys a generic off-the-shelf awareness course and reports poor engagement. Which design principle does NIST identify?
- 402. Material developers ask what question should guide them. Which pairing does NIST give for awareness and for training respectively?
- 403. Which two groups does NIST include in the audience for awareness, beyond permanent employees? Choose two.
- 404. An awareness session is written to be usable by any organisation in any sector. Which risk does NIST attach to that approach?
- 405. Which two items does NIST say must be complete before implementation of an awareness and training programme begins? Choose two.
- 406. Business unit managers are surprised to receive a charge for the new awareness programme. Which implementation step did NIST expect?
- 407. Which two changes does NIST name as making an awareness and training programme obsolete if unattended? Choose two.
- 408. Which two data items does NIST say an automated awareness and training tracking system should capture? Choose two.
- 409. Tracking shows a gap between recorded training status and the organisation's standard. Which three follow-up actions does NIST name?
- 410. A feedback form asks only whether attendees enjoyed the session. Which two dimensions does NIST say a feedback strategy should also address? Choose two.
- 411. Which behaviour does NIST list as an indicator that an awareness programme is genuinely supported?
- 412. Which two metrics does NIST offer as evidence of improving workforce security performance? Choose two.
- 413. Which two of the four interdependent components of a security performance measurement programme does NIST name? Choose two.
- 414. An organisation with no documented procedures struggles to produce meaningful security metrics. Which explanation does NIST give?
- 415. Why does NIST place senior management support as the foundation of a security metrics programme rather than as one contributor among many?
- 416. NIST groups security metrics by the three questions they answer. Which set is correct?
- 417. A programme manager reports the percentage of systems that have been authorised. Which type of metric is this?
- 418. A manager measures the elapsed time between a major system change and the system's renewed authorisation. Which type of metric is this?
- 419. Why does NIST describe mission impact metrics as the hardest to generate?
- 420. An immature security programme attempts to report mission impact metrics and finds it cannot. Which explanation does NIST give?
- 421. NIST describes evidence in a metrics programme evolving through four stages. Which sequence is correct?
- 422. Which two attributes does NIST require of a metric chosen for initial implementation? Choose two.
- 423. A manager measures a process that does not yet exist. What does NIST say about the result?
- 424. Which two items does NIST say must be documented alongside each metric? Choose two.
- 425. An organisation assigns weights to its security metrics. On what does NIST say those weights should be based?
- 426. A metric shows that only a third of security plans are approved, but nobody can say why. Which remedy does NIST describe?
- 427. Which two causes of poor control performance does NIST name that a purely technical investigation would miss? Choose two.
- 428. Which three activities does NIST include in analysing security measurement data?
- 429. Which two corrective actions does NIST name in response to a measured performance gap? Choose two.
- 430. NIST orders candidate corrective actions before selecting among them. Which ordering does it prescribe?
- 431. Having prioritised a list of corrective actions, how many does NIST suggest taking forward for full cost-benefit analysis?
- 432. Which benefit does NIST attribute to measuring performance frequently rather than annually?
- 433. Which two things does NIST say a metrics implementation plan should establish? Choose two.
- 434. A manager assumes metrics can only justify additional spending. Which further use does NIST identify?
- 435. Which two existing data sources does NIST say security metrics can be derived from? Choose two.
- 436. NIST identifies people as arguably the weakest element in securing systems. Which controls does it name as those that address the risk people introduce?
- 437. Which two items does NIST expect enterprise-level policy to cover for the awareness and training programme? Choose two.
- 438. Which sequence correctly describes NIST's six-step continuous monitoring process?
- 439. A monitoring programme collects large volumes of data but has no defined process for acting on it. How does NIST weigh these two aspects?
- 440. Which two things must a continuous monitoring strategy maintain, according to SP 800-137? Choose two.
- 441. Which two things does establishing a continuous monitoring programme settle, under SP 800-137? Choose two.
- 442. Monitoring produces a finding that a control is ineffective. Which two categories of response does SP 800-137 permit? Choose two.
- 443. How does SP 800-137 contrast an initial authorisation with continuous monitoring?
- 444. An organisation proposes assessing every aspect of every control continuously. What does SP 800-137 say?
- 445. In which circumstance does SP 800-137 identify sampling of security objects as particularly efficient?
- 446. An organisation sets one monitoring frequency and applies it to every metric permanently. Which two points does SP 800-137 make? Choose two.
- 447. Which two events does SP 800-137 say should cause monitoring priorities to be adjusted? Choose two.
- 448. Which advantage does SP 800-137 attribute to automated monitoring tools over human analysts?
- 449. How does SP 800-137 describe the intended relationship between automation and security professionals?
- 450. A monitoring programme is built entirely around the data the organisation can already collect automatically. Which caution does SP 800-137 give?
- 451. An organisation deploys sophisticated monitoring technology but its staff routinely bypass the surrounding procedures. What does SP 800-137 say results?
- 452. Which two capabilities does SP 800-137 say to look for when selecting continuous monitoring tools? Choose two.
- 453. An organisation is deciding how far to automate its monitoring. Which two considerations does SP 800-137 raise? Choose two.
- 454. Which two continuous monitoring responsibilities does SP 800-137 assign to the risk executive function? Choose two.
- 455. Which two duties does SP 800-137 assign to the senior information security officer within continuous monitoring? Choose two.
- 456. Which two decisions does SP 800-137 assign to the authorising official in continuous monitoring? Choose two.
- 457. Which two continuous monitoring duties does SP 800-137 place with the system owner? Choose two.
- 458. Beyond monitoring the controls it provides, which further duty does SP 800-137 place on a common control provider?
- 459. In what order does SP 800-137 say the security control assessor produces and uses the security assessment plan?
- 460. A monitoring strategy states only that it will be reviewed annually. Which further element does SP 800-137 require?
- 461. Which two things is a monitoring strategy checked for when it is reviewed, under SP 800-137? Choose two.
- 462. Where does SP 800-137 say the organisation-wide monitoring strategy and its general implementation procedures are typically developed?
- 463. An organisation's monitoring strategy is drafted at the business process tier. What does SP 800-137 require before it takes effect?
- 464. Which two subjects does SP 800-137 say training for monitoring roles may cover? Choose two.
- 465. Which two constraints does SP 800-137 say may limit the decisions of officials at the upper tiers? Choose two.
- 466. Which two inputs shape a system-level continuous monitoring strategy, according to SP 800-137? Choose two.
- 467. Which three things does system-level continuous monitoring address under SP 800-137?
- 468. An organisation believes only an external firm can perform an independent control assessment. What does NIST actually require of assessor independence?
- 469. Which four things does monitoring at the system tier confirm about controls, under SP 800-137?
- 470. What role does SP 800-137 give to metrics and dashboards at the upper tiers of an organisation?
- 471. Which two documents does SP 800-137 say a well-run monitoring programme keeps current, rather than letting them age between authorisations? Choose two.
- 472. A supply chain programme sets itself the objective of eliminating supply chain risk. How does NIST frame the correct objective?
- 473. Which two factors does NIST say should determine how deep and mature a supply chain risk capability needs to be? Choose two.
- 474. Which two examples does NIST give of non-adversarial supply chain threats? Choose two.
- 475. NIST splits supply chain vulnerabilities into external and internal. Which pairing is correct?
- 476. Which two difficulties does NIST identify in dealing with supply chain vulnerabilities? Choose two.
- 477. A single cloud provider suffers a large-scale outage and several organisations in the same supply chain are disrupted at once. Which supply chain property does NIST use this to illustrate?
- 478. Which model does NIST recommend for distributing accountability in supply chain risk management?
- 479. An organisation forms a cross-functional supply chain risk team and disbands the risk responsibilities previously held within each discipline. What does NIST say about this?
- 480. Which two acquisition routes does NIST say supply chain risk must also be addressed for, beyond formal procurement? Choose two.
- 481. NIST identifies a critical first step in managing supply chain risk. What is it?
- 482. NIST recommends segmenting suppliers into groupings. What is the purpose of that segmentation?
- 483. Which two things does NIST say supplier inventory and mapping reveals? Choose two.
- 484. Which two acquisition practices does NIST name for managing supply chain risk? Choose two.
- 485. A project timeline allows no room for supplier security assessment before award. What does NIST say organisations should do?
- 486. A procurement for a security service is to be awarded on a lowest price technically acceptable basis. What does NIST advise?
- 487. Which two participants does NIST say must be on the acquisition team so the security view is present when requirements are set? Choose two.
- 488. Why does NIST place determination of criticality at the planning step of a procurement rather than later?
- 489. At which step of the procurement process does NIST place robust due diligence research producing a supplier risk profile?
- 490. A team treats its initial due diligence questionnaire as the complete picture of supplier risk. What warning does NIST give?
- 491. During market research an organisation finds only two viable suppliers exist worldwide for a needed component. How does NIST treat that observation?
- 492. Which two post-award changes does NIST say should be monitored because they alter supply chain risk exposure? Choose two.
- 493. A supplier's risk profile deteriorates beyond what any mitigation can bring back within tolerance. Which contractual provision does NIST say should exist?
- 494. An organisation assesses a supplier thoroughly at award and never again during a five-year contract. Which contract management practice does NIST expect?
- 495. A supplier suffers a disruption but does not report it, arguing it was not serious. Which contract provision does NIST say should have prevented the dispute?
- 496. Which two validation methods does NIST name for supplier assurance, and what governs how rigorous the choice should be? Choose two.
- 497. An organisation wants security requirements to be more than a post-award discussion with the winning bidder. Which mechanism does NIST describe?
- 498. Which two acquisition security techniques does NIST name for protecting against tampering and counterfeiting in transit? Choose two.
- 499. Which two supply chain risk activities does NIST map to the operate and maintain phase of the procurement process? Choose two.
- 500. Requirements are flowed down to subcontractors but nothing checks whether they are met. Which linkage does NIST require?
- 501. Which two benefits does NIST attribute to sharing supply chain risk information within a community? Choose two.
- 502. What does NIST ask suppliers to provide with products, including hardware that carries logic?
- 503. Which three things does a security learning programme strategic plan set out, according to NIST?
- 504. A learning programme manager struggles to justify the programme to executives. Which linkage does NIST say demonstrates why it is needed?
- 505. At what point in the funding process does NIST expect the learning programme strategy to be reviewed and agreed?
- 506. Which two workforce groups does NIST specifically say a learning plan should provide for? Choose two.
- 507. An organisation with an existing learning programme wants to reshape it. Which analysis does NIST recommend first?
- 508. NIST separates policy from procedure by function. Which pairing is correct?
- 509. Which two benefits does NIST attribute to establishing learning programme policies and procedures? Choose two.
- 510. Which policy pattern does NIST describe for enforcing awareness training completion?
- 511. When does NIST's example policy require role-based training for staff with significant security responsibilities?
- 512. An organisation allows exceptions to its training requirement but does not say who may grant them. Which element does NIST's example policy include?
- 513. Which acronym does NIST recommend as the test for a learning programme's goals, and what does it stand for?
- 514. A learning programme sets a goal of reducing susceptibility to social engineering and runs a phishing exercise in support. Which element of the strategy model is the exercise?
- 515. A review finds several learning activities that cannot be traced to any stated objective or goal. What does NIST say about such activities?
- 516. An organisation measures its learning programme purely by regulatory completion rates. Which three further effects does NIST say must also be measured?
- 517. Why does NIST treat training records as carrying heightened sensitivity?
- 518. Which risks does NIST ask a learning programme manager to identify and manage, beyond the risks the programme teaches about?
- 519. NIST distinguishes a learning goal from a learning objective. Which pairing is correct?
- 520. What distinguishes a learning outcome from a learning goal in NIST's terms?
- 521. A programme tests learners immediately after a course and reports high scores. Which additional measurement does NIST recommend, and what does it show?
- 522. Which two longitudinal behaviours does NIST offer as evidence of a learning programme's impact? Choose two.
- 523. Which measurement does NIST say demonstrates that staff can actually recognise and report a potential security event, which completion rates cannot show?
- 524. Which two organisational changes following technical training does NIST offer as measurements? Choose two.
- 525. What did NIST's research find about the learning metrics organisations actually use?
- 526. NIST divides the learning audience into three overlapping segments. Which set is correct?
- 527. Why does NIST say privileged access account holders receive training beyond the all-user programme?
- 528. How does NIST describe the relationship between privileged access holders and those with significant security responsibilities?
- 529. Which learning duty does NIST assign to managers in relation to staff with significant security responsibilities?
- 530. An employee completes the general awareness module but does not know the specific rules governing the application they use daily. Which managerial duty does NIST identify?
- 531. Which two responsibilities does NIST assign to an ordinary system user? Choose two.
- 532. Which sequence correctly describes the six phases of the security services life cycle?
- 533. Which three activities does NIST place in the initiation phase of the security services life cycle?
- 534. An organisation is about to choose a security service provider without knowing what its current environment costs or achieves. Which life cycle phase has been skipped?
- 535. Which three outputs does the solution phase of the security services life cycle produce?
- 536. A service has gone live and the organisation considers the engagement complete. What does NIST say the operations phase requires?
- 537. Which two activities does NIST place in the closeout phase of the security services life cycle? Choose two.
- 538. Why does NIST ask programme managers to identify the triggers for a replacement security service in advance?
- 539. Which two management tools does NIST name for making a security service provider accountable for results? Choose two.
- 540. NIST groups security services into three categories. Which set is correct?
- 541. Which two dependencies does NIST identify for operational security services? Choose two.
- 542. Two organisations run the same application but select different control mixes. Which two factors does NIST say determine the appropriate blend? Choose two.
- 543. Why might the same system warrant different controls in two different organisations, according to NIST?
- 544. A decision to outsource a security service is taken purely on cost. Which two consequences does NIST warn may follow? Choose two.
- 545. Which two of NIST's six issue categories for acquiring security services are correct? Choose two.
- 546. On funding decisions for security services, what does NIST say the focus should be?
- 547. An organisation engages an external security provider and finds long-established internal controls no longer make sense. How does NIST characterise this?
- 548. Which two questions does NIST include in provider evaluation about past performance? Choose two.
- 549. Which two commercial terms does NIST say to understand before signing with a security service provider? Choose two.
- 550. A provider's contingency planning policy is weaker than the organisation's own. Which question does NIST direct the organisation to ask?
- 551. Which two questions does NIST direct at a provider that will hold the organisation's data alongside other customers'? Choose two.
- 552. Which two personnel questions does NIST include in evaluating a security service provider? Choose two.
- 553. Which aspect of a provider's own position does NIST say should be evaluated as part of the strategic and mission questions?
- 554. Which two organisational considerations does NIST list before selecting a security product? Choose two.
- 555. Which two product considerations does NIST list for security product selection? Choose two.
- 556. Which two vendor considerations does NIST list for security product selection? Choose two.
- 557. Which selection preference does NIST express for security products where an evaluated option exists?
- 558. What does NIST say a cost-benefit analysis for security product selection should include, beyond the alternatives under consideration?
- 559. Which two roles does NIST include among those involved in selecting security products and services? Choose two.
- 560. An organisation begins a security service procurement by comparing vendors' offerings. Which prior step does NIST prescribe?
- 561. Which two delivery arrangements does NIST identify for a security service, beyond a commercial provider? Choose two.
- 562. What does NIST identify as the purpose of configuration management in security terms?
- 563. Which three kinds of change does NIST say the configuration management process covers?
- 564. Why does NIST require changes to be tested before implementation?
- 565. A manager argues a formal change process is not worth its overhead for a small organisation. Which economic argument does NIST make?
- 566. Which two things does the baseline configuration control require an organisation to maintain? Choose two.
- 567. A change log records that each change occurred but says nothing about its effect. Which control requirement is unmet?
- 568. What standard does the configuration settings control set for how security settings should be configured?
- 569. Which two elements does the least functionality control require? Choose two.
- 570. NIST notes that many system functions and services are provided by default. What does it ask organisations to do about them?
- 571. How does the access restrictions for change control differ from configuration change control?
- 572. Which two disciplines does NIST say configuration management interlocks with, beyond risk management? Choose two.
- 573. Why does NIST say the configuration management process can only begin after the initial control baseline is selected?
- 574. Which definition of security accreditation does NIST give?
- 575. A significant change is identified through the configuration management process. What does NIST say must follow?
- 576. Which principle does NIST say change management must address so that changes reach production only after being tested and approved?
- 577. Which two configuration management responsibilities does NIST assign to the system owner? Choose two.
- 578. Which two responsibilities does NIST assign to the configuration control review board? Choose two.
- 579. Which two daily configuration management duties does NIST assign to the configuration manager? Choose two.
- 580. What is the information systems security officer's role in relation to the configuration control board?
- 581. NIST assigns system users a defined role in configuration management. What is it?
- 582. Which two sources of change initiation does NIST identify beyond users and system owners? Choose two.
- 583. Which two questions does NIST's impact analysis of a change request ask? Choose two.
- 584. Which three decisions can conclude a change request under NIST's process?
- 585. Which staffing arrangement does NIST recommend for moving an approved change into production, and why?
- 586. Which two checks does NIST describe under continuous monitoring within the configuration management process? Choose two.
- 587. Which three steps does NIST describe for patch management within the configuration process?
- 588. How many steps does the Risk Management Framework have, and what distinguishes the first?
- 589. What does categorising a system determine, and what does that determination drive?
- 590. An organisation plans to select the baseline first and tailor it as a separate later exercise. How does the RMF define the Select step?
- 591. Which three things does the RMF Assess step determine about controls?
- 592. What determination does the RMF Authorize step make, and what can it cover?
- 593. Which two activities does the RMF Monitor step include beyond assessing control effectiveness? Choose two.
- 594. An organisation with an agile delivery model wants to iterate between RMF steps rather than run them once in order. What does SP 800-37 permit?
- 595. How does SP 800-37 balance the obligation to perform RMF tasks against organisational flexibility?
- 596. A team wants to select, tailor, implement and assess controls progressively as a system is built rather than in a single pass. Is this permitted?
- 597. Which two things does SP 800-37 require before an organisation re-enters the RMF at a chosen step? Choose two.
- 598. Which three designations does NIST use for controls, and what governs the designation?
- 599. Why does SP 800-37 require traceability from each control back to the requirement it satisfies?
- 600. Which two organisation-level RMF Prepare tasks does SP 800-37 name? Choose two.
- 601. Why does SP 800-37 require common controls to be identified, documented and published?
- 602. Which two sources does an organisation-level risk assessment draw on, under SP 800-37? Choose two.
- 603. Which architectural question does SP 800-37 give as an example for an organisation-level risk assessment?
- 604. Why does SP 800-37 ask risk assessment to account for variability across an organisation?
- 605. Which two things does a system security plan contain, according to NIST?
- 606. How does NIST characterise system security plans, and what accompanies them for controls not yet in place?
- 607. An organisation produces its system security plan as an output of the authorisation process. What sequence does NIST require?
- 608. A small organisation assigns one individual to several security planning roles. Which caution does NIST give?
- 609. Which two decisions does NIST assign to the information owner? Choose two.
- 610. An information owner shares data with a partner organisation and considers protection now the partner's responsibility. What does NIST say?
- 611. Which two responsibilities does NIST assign to the system owner in relation to the security plan? Choose two.
- 612. Which two things do rules of behaviour do, according to NIST? Choose two.
- 613. How does NIST require a user's acceptance of the rules of behaviour to be recorded?
- 614. Why does NIST say the acknowledgement of the rules of behaviour matters as much as the text itself?
- 615. Which two topics does NIST list as typically covered by rules of behaviour? Choose two.
- 616. A drafter proposes to reproduce the entire security policy inside the rules of behaviour. What does NIST advise instead?
- 617. Who approves a system security plan before authorisation, and what makes that approval meaningful?
- 618. Why must a system and its information be categorised before the security plan is written?
- 619. Which two statements about defining a system's security boundary are correct under NIST guidance? Choose two.
- 620. How does NIST define a subsystem?
- 621. Which two activities does NIST include in tailoring a control baseline? Choose two.
- 622. An organisation tailors its control baseline but records only the final control set. Which requirement is unmet?
- 623. Which two local conditions does NIST say may be used to tailor a control baseline? Choose two.
- 624. How does NIST define a compensating security control?
- 625. Which two of the three conditions governing the use of a compensating control does NIST state? Choose two.
- 626. A system team decides to substitute a compensating control and records it in their own change log only. Which requirement is unmet?
- 627. Which two scopes can a common control cover, according to NIST? Choose two.
- 628. To whom does NIST say responsibility for developing, implementing and assessing a common control should be assigned?
- 629. Which efficiency does NIST attribute to the common control approach?
- 630. What risk does NIST identify as arising from widespread dependence on common controls?
- 631. How does NIST recommend common controls be handled across many system security plans?
- 632. Which two organisational conditions does NIST say make identification of common controls work? Choose two.
- 633. What does scoping guidance provide, and what must the security plan record about its use?
- 634. Who must review and approve the application of scoping guidance to a system's controls?
- 635. Which two roles does NIST say must be involved in security categorisation, showing it is not a single team's task? Choose two.
- 636. On what basis is a system rated low, moderate or high against each security objective?
- 637. How does NIST define adequate security?
- 638. A minor application runs inside a larger general support system. What does NIST say about its security plan?
- 639. Which security planning duty does NIST assign to the chief information officer regarding controls the organisation offers for inheritance?
- 640. Which coordination duty does NIST assign to the senior information security officer in security planning?
- 641. How does NIST define a system interconnection?
- 642. Which two levels of system interconnection does NIST describe? Choose two.
- 643. Which specific risk does NIST identify when two systems are interconnected?
- 644. What does NIST require before an organisation connects its system to another system?
- 645. Which two things does a formal interconnection agreement specify, according to NIST? Choose two.
- 646. Why does NIST require each interconnected system's controls to be evaluated against the other's requirements?
- 647. Which two purposes does NIST give for maintaining clear lines of communication between interconnected parties? Choose two.
- 648. How often does NIST say the security controls on an interconnection should be reviewed?
- 649. Two systems with different configurations and control sets are to be interconnected. Why does NIST say the resulting risk must be weighed carefully?
- 650. Which four phases make up the life cycle management approach for interconnecting systems?
- 651. Which two participants does NIST include in a joint planning team for an interconnection? Choose two.
- 652. Which three factors does NIST say the business case for an interconnection should weigh?
- 653. Why does NIST say each party should consider reauthorising its system before establishing an interconnection?
- 654. Which two items does NIST say an interconnection security agreement contains, beyond the technical and security requirements? Choose two.
- 655. Which two matters does a memorandum of understanding for an interconnection settle, according to NIST? Choose two.
- 656. Who must sign the memorandum of understanding for an interconnection, and why does it matter?
- 657. Why does NIST say interconnection agreements themselves need protection?
- 658. Which three outcomes are available to an authorising official reviewing a proposed interconnection?
- 659. Under what condition does NIST permit the two interconnection documents to be combined, and what must be preserved?
- 660. Which two items does NIST say an interconnection implementation plan must identify? Choose two.
- 661. Which two things does NIST say both parties should examine closely when a new interconnection is activated? Choose two.
- 662. Which two activities does NIST include in maintaining an established interconnection? Choose two.
- 663. Which three things does NIST say a written notice of planned disconnection should describe?
- 664. Which two considerations govern the scheduling of a planned disconnection, according to NIST? Choose two.
- 665. What must both organisations agree about shared data when an interconnection is disconnected?
- 666. Which two conditions does NIST attach to an emergency disconnection performed without written notice? Choose two.
- 667. Which two things does NIST require after an emergency disconnection? Choose two.
- 668. An interconnection was terminated because of an attack and both parties now wish to restore it. Which two steps does NIST require first? Choose two.
- 669. An interconnection has been down for more than ninety days and the parties want to restore it. What does NIST require?
- 670. How does NIST relate assessment to measurement in SP 800-55?
- 671. Which two kinds of assessment does NIST name alongside risk assessment when evaluating security risk? Choose two.
- 672. How does NIST characterise the relationship between programme assessments, control assessments and risk assessment?
- 673. Which tension does NIST identify in choosing how many security measures to collect?
- 674. Which three methods does NIST name for collecting security data?
- 675. NIST describes a simulated phishing test as an example of which data collection method?
- 676. What distinguishes observational data in NIST's account of measurement?
- 677. Which sampling method gives every item an equal chance of selection, aiming for an unbiased picture?
- 678. Which two characteristics does NIST attribute to stratified sampling? Choose two.
- 679. Which weakness does NIST identify in systematic sampling?
- 680. How does NIST characterise a qualitative assessment in SP 800-55?
- 681. An organisation reports that it is at level three on a maturity model. How does NIST classify that number?
- 682. Which example does NIST give of a quantitative assessment whose values keep their meaning outside the assessment?
- 683. Which results does NIST count as measures for the purposes of SP 800-55?
- 684. Which two limitations does NIST attach to qualitative assessment, despite its ease of use? Choose two.
- 685. Why does NIST say an organisation should consider its motivations before choosing between quantitative and qualitative assessment?
- 686. Which measure does NIST say gives sharper insight into patching performance, and why?
- 687. An organisation early in its measurement journey relies on a risk matrix. What progression does NIST describe?
- 688. Which three properties does NIST require of meaningful security measures?
- 689. How does NIST say measurement strengthens governance?
- 690. Which pairing correctly matches metric level to the kind of decision it supports?
- 691. Which two characteristics does NIST require of a meaningful metric? Choose two.
- 692. What consequence does NIST attribute to poorly chosen quantitative metrics?
- 693. Which test does NIST give for deciding whether to keep a quantitative metric?
- 694. Why does NIST emphasise keeping metrics consistent over time?
- 695. How does NIST relate key risk indicators and key performance indicators to metrics generally?
- 696. For evaluating cybersecurity awareness training, which approach does NIST prefer?
- 697. Which two conditions does NIST say organisation-level measurement requires? Choose two.
- 698. NIST states that security cannot be measured perfectly. Which reason does it give, and what does it advise instead?
- 717. An organisation contracts a provider to perform incident detection and response. Which two things does NIST say the contract must define? Choose two.
- 718. Which two restrictions does NIST say an incident response provider contract should state? Choose two.
- 720. Which risk does NIST attach to engaging an incident response provider, and which deterrent does it name?
- 740. Which three uses does the Community Profile give for automatically updated hardware and software inventories?
- 755. An organisation delivers role-based training covering technical skills but omitting what each role must do during an incident. Which recommendation is unmet?
- 761. Which two aspects of external provider behaviour does the Community Profile say should be monitored? Choose two.
- 763. Why does the Community Profile recommend monitoring configurations against security baselines?
- 771. Which three sources does the Community Profile name for acquiring vulnerability disclosures about the organisation's own technologies?
- 815. Which example does NIST give of an incident type a third party might be authorised to contain automatically on the organisation's behalf?
- 831. Which two recommendations does NIST make about communicating with suppliers during recovery? Choose two.
- 844. Which CSF 2.0 supply chain outcome addresses the involvement of suppliers in incident work?
- 866. Which sequence matches NIST's seven-step contingency planning process?
- 867. Where in the system life cycle does NIST place the contingency planning policy and the business impact analysis, and why there?
- 870. With which functions does NIST say contingency planning must be coordinated?
- 917. Which two less obvious costs does NIST say a contingency budget must cover? Choose two.
- 924. Which check does NIST require when evaluating whether an alternate site is adequate?
- 929. How does NIST distinguish contingency training from awareness?
- 932. Beyond individual duties, which topic does NIST expect contingency training to cover?
- 939. Which two things does NIST require of every test and exercise?
- 942. To which organisational process does NIST tie contingency plan maintenance?
- 970. Which judgement does NIST require after reconstitution?
- 974. Which three elements does NIST say a test, training and exercise programme needs to be repeatable rather than ad hoc?
- 980. Which by-product does NIST attribute to running a training session?