Study. uk . com
  1. Home
  2. All questions
  3. Security program

CISM study material: Security program

379 questions of the 1000 in the CISM — Certified Information Security Manager quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 46. An assessment repeatedly finds the same deficiencies year after year, with no record of what was done about earlier findings. Which senior security officer responsibility is not being discharged?
  2. 50. Two employees commit the same policy violation, and one is dismissed while the other receives no sanction. Which role owns the practice that failed here?
  3. 52. A procurement completes without any security requirements in the contract, and the security office learns of it only at go-live. Which governance relationship failed?
  4. 60. A manager sets up ongoing monitoring of the security programme itself. Which two questions does NIST say that monitoring should answer? Choose two.
  5. 66. Monitoring consistently shows that one control family underperforms, but funding allocations the following year are unchanged. Which governance practice is not working?
  6. 80. A manager must explain what an authorisation boundary determines. Which answer is correct?
  7. 86. An organisation is preparing to rely on an external service provider. Which two things does SP 800-39 say it must establish? Choose two.
  8. 91. A project plans to gather functional requirements first and add security requirements once the design is stable. Why does SP 800-39 object?
  9. 93. A system cannot achieve the level of trustworthiness needed from its technical controls alone. What does SP 800-39 say the organisation should do?
  10. 96. A manager is aligning security activities to the system development life cycle. Which sequence of phases does NIST describe?
  11. 97. A programme treats its life cycle as strictly one-directional, refusing to revisit earlier phases. What does NIST say about this?
  12. 98. Servers are being retired and sent for disposal. Which two actions does SP 800-39 expect at this life cycle phase? Choose two.
  13. 99. A system is about to go live and the project manager proposes assessing control effectiveness after six months of operation. Why does SP 800-39 place that assessment earlier?
  14. 103. A programme discovers cost overruns only at delivery. Which investment phase and mechanism was intended to catch them earlier?
  15. 104. Security drivers differ across the investment life cycle. Which two pairings are correct? Choose two.
  16. 105. An organisation begins the seven-step process for integrating security into capital planning. What is the first step?
  17. 108. A security manager wants weaknesses found during assessment to actually attract funding. Which mechanism does NIST describe for connecting the two?
  18. 170. During design, an assessment shows a proposed component carries known weaknesses that a comparable alternative does not. What does SP 800-39 identify as the advantage of switching at this point?
  19. 223. Which two authorisation decisions can risk assessment results support, according to SP 800-30? Choose two.
  20. 238. An organisation maps only the risks its suppliers pose to it. Which point does SP 800-39 make about external risk relationships?
  21. 242. An organisation approves exceptions to policy in a change ticket and takes no further action. Which CSF 2.0 expectation is not being met?
  22. 243. A supplier's hardware is verified for authenticity and integrity only after it has been racked and connected. Which CSF 2.0 outcome does this fail?
  23. 245. An organisation applies the same assurance questionnaire to every one of its 900 suppliers and cannot complete the programme. Which CSF 2.0 outcome would address this?
  24. 246. A supplier is onboarded and the first security review takes place six months into the contract. Which CSF 2.0 outcome does this arrangement miss?
  25. 247. A supplier contract ends and the supplier retains administrative access and copies of organisational data for months afterwards. Which CSF 2.0 outcome addresses this?
  26. 263. IR 8286 warns two kinds of control must not be confused. Which pairing describes them correctly?
  27. 272. An organisation cannot say with confidence which devices it operates or where its data resides. What consequence does IR 8286 draw?
  28. 324. A mitigation cannot be implemented immediately because the necessary resources are unavailable. Which two things does IR 8286 say the corrective action plan records? Choose two.
  29. 346. How does SP 800-30 describe the role of security categorisation within risk assessment?
  30. 362. Which organisation-tier vulnerability does SP 800-30 illustrate with the example of subverted components entering the estate?
  31. 373. An organisation maintains a single combined asset list. Which two further inventories does CSF 2.0 expect to be maintained separately? Choose two.
  32. 374. A team ranks assets purely by replacement cost. Which basis does CSF 2.0 prescribe for prioritising assets?
  33. 375. An access review confirms permissions are enforced technically but finds no policy defining them and no periodic review. Which two elements of the CSF 2.0 outcome are missing? Choose two.
  34. 376. An organisation delivers one annual awareness module to everyone including its security engineers and developers. Which CSF 2.0 expectation is unmet?
  35. 377. A data protection programme addresses data at rest and data in transit. Which two further outcomes does CSF 2.0 name under Data Security? Choose two.
  36. 378. An organisation adopts a secure development standard and considers the outcome achieved. Which further expectation does CSF 2.0 attach?
  37. 379. Security expectations are communicated to suppliers verbally at kickoff meetings and recorded in no agreement. Which CSF 2.0 outcome does this fail?
  38. 380. An organisation monitors its own networks and endpoints continuously but performs no monitoring of the managed service provider operating part of its estate. Which CSF 2.0 outcome is missing?
  39. 381. Which pairing correctly describes a common control and a common control provider in NIST usage?
  40. 382. Which two decisions taken at the organisation tier does SP 800-39 say constrain what the lower tiers can do? Choose two.
  41. 383. A manager asks where organisation-level security requirements are recorded, and where such requirements may originate. Which answer is correct?
  42. 384. Which four things does a plan of action and milestones do for security weaknesses found in programmes and systems?
  43. 385. Which two patterns in a plan of action and milestones does NIST identify as signs of a healthy process? Choose two.
  44. 386. Which two properties does NIST require of good security measures? Choose two.
  45. 387. A team collects security measurement data already summarised by business unit. Which practice does NIST recommend instead, and why?
  46. 388. An organisation operates a change board that reviews cost and schedule but has no security participant. Which NIST expectation is not met?
  47. 389. A team deploys vendor patches straight to production on the vendor's assurance that they are safe. Which NIST expectation does this skip?
  48. 390. Which observable trend does NIST offer as evidence that configuration management is working?
  49. 391. Which two uses does NIST identify for incident statistics in managing a security programme? Choose two.
  50. 392. Network monitoring data is reviewed in isolation by the operations team. Which improvement does NIST recommend?
  51. 393. Which four things does continuous assessment do after a system's initial authorisation?
  52. 394. A manager must explain to the training team the difference between awareness and training as NIST defines them. Which statement is correct?
  53. 395. Awareness material is criticised for not explaining how to configure a control. How does NIST define the scope of awareness content?
  54. 396. Which sequence correctly describes the NIST learning continuum, with certification's place in it?
  55. 397. An employee disputes a sanction on the ground that they were never told the rule existed. Which role of awareness does NIST identify that this case illustrates?
  56. 398. Which two things does NIST say an awareness communications plan identifies? Choose two.
  57. 399. A candidate presents a certificate showing they attended a five-day course. What does NIST say such a certificate establishes?
  58. 400. Which sequence correctly describes the three major steps of developing an awareness and training programme?
  59. 401. An organisation buys a generic off-the-shelf awareness course and reports poor engagement. Which design principle does NIST identify?
  60. 402. Material developers ask what question should guide them. Which pairing does NIST give for awareness and for training respectively?
  61. 403. Which two groups does NIST include in the audience for awareness, beyond permanent employees? Choose two.
  62. 404. An awareness session is written to be usable by any organisation in any sector. Which risk does NIST attach to that approach?
  63. 405. Which two items does NIST say must be complete before implementation of an awareness and training programme begins? Choose two.
  64. 406. Business unit managers are surprised to receive a charge for the new awareness programme. Which implementation step did NIST expect?
  65. 407. Which two changes does NIST name as making an awareness and training programme obsolete if unattended? Choose two.
  66. 408. Which two data items does NIST say an automated awareness and training tracking system should capture? Choose two.
  67. 409. Tracking shows a gap between recorded training status and the organisation's standard. Which three follow-up actions does NIST name?
  68. 410. A feedback form asks only whether attendees enjoyed the session. Which two dimensions does NIST say a feedback strategy should also address? Choose two.
  69. 411. Which behaviour does NIST list as an indicator that an awareness programme is genuinely supported?
  70. 412. Which two metrics does NIST offer as evidence of improving workforce security performance? Choose two.
  71. 413. Which two of the four interdependent components of a security performance measurement programme does NIST name? Choose two.
  72. 414. An organisation with no documented procedures struggles to produce meaningful security metrics. Which explanation does NIST give?
  73. 415. Why does NIST place senior management support as the foundation of a security metrics programme rather than as one contributor among many?
  74. 416. NIST groups security metrics by the three questions they answer. Which set is correct?
  75. 417. A programme manager reports the percentage of systems that have been authorised. Which type of metric is this?
  76. 418. A manager measures the elapsed time between a major system change and the system's renewed authorisation. Which type of metric is this?
  77. 419. Why does NIST describe mission impact metrics as the hardest to generate?
  78. 420. An immature security programme attempts to report mission impact metrics and finds it cannot. Which explanation does NIST give?
  79. 421. NIST describes evidence in a metrics programme evolving through four stages. Which sequence is correct?
  80. 422. Which two attributes does NIST require of a metric chosen for initial implementation? Choose two.
  81. 423. A manager measures a process that does not yet exist. What does NIST say about the result?
  82. 424. Which two items does NIST say must be documented alongside each metric? Choose two.
  83. 425. An organisation assigns weights to its security metrics. On what does NIST say those weights should be based?
  84. 426. A metric shows that only a third of security plans are approved, but nobody can say why. Which remedy does NIST describe?
  85. 427. Which two causes of poor control performance does NIST name that a purely technical investigation would miss? Choose two.
  86. 428. Which three activities does NIST include in analysing security measurement data?
  87. 429. Which two corrective actions does NIST name in response to a measured performance gap? Choose two.
  88. 430. NIST orders candidate corrective actions before selecting among them. Which ordering does it prescribe?
  89. 431. Having prioritised a list of corrective actions, how many does NIST suggest taking forward for full cost-benefit analysis?
  90. 432. Which benefit does NIST attribute to measuring performance frequently rather than annually?
  91. 433. Which two things does NIST say a metrics implementation plan should establish? Choose two.
  92. 434. A manager assumes metrics can only justify additional spending. Which further use does NIST identify?
  93. 435. Which two existing data sources does NIST say security metrics can be derived from? Choose two.
  94. 436. NIST identifies people as arguably the weakest element in securing systems. Which controls does it name as those that address the risk people introduce?
  95. 437. Which two items does NIST expect enterprise-level policy to cover for the awareness and training programme? Choose two.
  96. 438. Which sequence correctly describes NIST's six-step continuous monitoring process?
  97. 439. A monitoring programme collects large volumes of data but has no defined process for acting on it. How does NIST weigh these two aspects?
  98. 440. Which two things must a continuous monitoring strategy maintain, according to SP 800-137? Choose two.
  99. 441. Which two things does establishing a continuous monitoring programme settle, under SP 800-137? Choose two.
  100. 442. Monitoring produces a finding that a control is ineffective. Which two categories of response does SP 800-137 permit? Choose two.
  101. 443. How does SP 800-137 contrast an initial authorisation with continuous monitoring?
  102. 444. An organisation proposes assessing every aspect of every control continuously. What does SP 800-137 say?
  103. 445. In which circumstance does SP 800-137 identify sampling of security objects as particularly efficient?
  104. 446. An organisation sets one monitoring frequency and applies it to every metric permanently. Which two points does SP 800-137 make? Choose two.
  105. 447. Which two events does SP 800-137 say should cause monitoring priorities to be adjusted? Choose two.
  106. 448. Which advantage does SP 800-137 attribute to automated monitoring tools over human analysts?
  107. 449. How does SP 800-137 describe the intended relationship between automation and security professionals?
  108. 450. A monitoring programme is built entirely around the data the organisation can already collect automatically. Which caution does SP 800-137 give?
  109. 451. An organisation deploys sophisticated monitoring technology but its staff routinely bypass the surrounding procedures. What does SP 800-137 say results?
  110. 452. Which two capabilities does SP 800-137 say to look for when selecting continuous monitoring tools? Choose two.
  111. 453. An organisation is deciding how far to automate its monitoring. Which two considerations does SP 800-137 raise? Choose two.
  112. 454. Which two continuous monitoring responsibilities does SP 800-137 assign to the risk executive function? Choose two.
  113. 455. Which two duties does SP 800-137 assign to the senior information security officer within continuous monitoring? Choose two.
  114. 456. Which two decisions does SP 800-137 assign to the authorising official in continuous monitoring? Choose two.
  115. 457. Which two continuous monitoring duties does SP 800-137 place with the system owner? Choose two.
  116. 458. Beyond monitoring the controls it provides, which further duty does SP 800-137 place on a common control provider?
  117. 459. In what order does SP 800-137 say the security control assessor produces and uses the security assessment plan?
  118. 460. A monitoring strategy states only that it will be reviewed annually. Which further element does SP 800-137 require?
  119. 461. Which two things is a monitoring strategy checked for when it is reviewed, under SP 800-137? Choose two.
  120. 462. Where does SP 800-137 say the organisation-wide monitoring strategy and its general implementation procedures are typically developed?
  121. 463. An organisation's monitoring strategy is drafted at the business process tier. What does SP 800-137 require before it takes effect?
  122. 464. Which two subjects does SP 800-137 say training for monitoring roles may cover? Choose two.
  123. 465. Which two constraints does SP 800-137 say may limit the decisions of officials at the upper tiers? Choose two.
  124. 466. Which two inputs shape a system-level continuous monitoring strategy, according to SP 800-137? Choose two.
  125. 467. Which three things does system-level continuous monitoring address under SP 800-137?
  126. 468. An organisation believes only an external firm can perform an independent control assessment. What does NIST actually require of assessor independence?
  127. 469. Which four things does monitoring at the system tier confirm about controls, under SP 800-137?
  128. 470. What role does SP 800-137 give to metrics and dashboards at the upper tiers of an organisation?
  129. 471. Which two documents does SP 800-137 say a well-run monitoring programme keeps current, rather than letting them age between authorisations? Choose two.
  130. 472. A supply chain programme sets itself the objective of eliminating supply chain risk. How does NIST frame the correct objective?
  131. 473. Which two factors does NIST say should determine how deep and mature a supply chain risk capability needs to be? Choose two.
  132. 474. Which two examples does NIST give of non-adversarial supply chain threats? Choose two.
  133. 475. NIST splits supply chain vulnerabilities into external and internal. Which pairing is correct?
  134. 476. Which two difficulties does NIST identify in dealing with supply chain vulnerabilities? Choose two.
  135. 477. A single cloud provider suffers a large-scale outage and several organisations in the same supply chain are disrupted at once. Which supply chain property does NIST use this to illustrate?
  136. 478. Which model does NIST recommend for distributing accountability in supply chain risk management?
  137. 479. An organisation forms a cross-functional supply chain risk team and disbands the risk responsibilities previously held within each discipline. What does NIST say about this?
  138. 480. Which two acquisition routes does NIST say supply chain risk must also be addressed for, beyond formal procurement? Choose two.
  139. 481. NIST identifies a critical first step in managing supply chain risk. What is it?
  140. 482. NIST recommends segmenting suppliers into groupings. What is the purpose of that segmentation?
  141. 483. Which two things does NIST say supplier inventory and mapping reveals? Choose two.
  142. 484. Which two acquisition practices does NIST name for managing supply chain risk? Choose two.
  143. 485. A project timeline allows no room for supplier security assessment before award. What does NIST say organisations should do?
  144. 486. A procurement for a security service is to be awarded on a lowest price technically acceptable basis. What does NIST advise?
  145. 487. Which two participants does NIST say must be on the acquisition team so the security view is present when requirements are set? Choose two.
  146. 488. Why does NIST place determination of criticality at the planning step of a procurement rather than later?
  147. 489. At which step of the procurement process does NIST place robust due diligence research producing a supplier risk profile?
  148. 490. A team treats its initial due diligence questionnaire as the complete picture of supplier risk. What warning does NIST give?
  149. 491. During market research an organisation finds only two viable suppliers exist worldwide for a needed component. How does NIST treat that observation?
  150. 492. Which two post-award changes does NIST say should be monitored because they alter supply chain risk exposure? Choose two.
  151. 493. A supplier's risk profile deteriorates beyond what any mitigation can bring back within tolerance. Which contractual provision does NIST say should exist?
  152. 494. An organisation assesses a supplier thoroughly at award and never again during a five-year contract. Which contract management practice does NIST expect?
  153. 495. A supplier suffers a disruption but does not report it, arguing it was not serious. Which contract provision does NIST say should have prevented the dispute?
  154. 496. Which two validation methods does NIST name for supplier assurance, and what governs how rigorous the choice should be? Choose two.
  155. 497. An organisation wants security requirements to be more than a post-award discussion with the winning bidder. Which mechanism does NIST describe?
  156. 498. Which two acquisition security techniques does NIST name for protecting against tampering and counterfeiting in transit? Choose two.
  157. 499. Which two supply chain risk activities does NIST map to the operate and maintain phase of the procurement process? Choose two.
  158. 500. Requirements are flowed down to subcontractors but nothing checks whether they are met. Which linkage does NIST require?
  159. 501. Which two benefits does NIST attribute to sharing supply chain risk information within a community? Choose two.
  160. 502. What does NIST ask suppliers to provide with products, including hardware that carries logic?
  161. 503. Which three things does a security learning programme strategic plan set out, according to NIST?
  162. 504. A learning programme manager struggles to justify the programme to executives. Which linkage does NIST say demonstrates why it is needed?
  163. 505. At what point in the funding process does NIST expect the learning programme strategy to be reviewed and agreed?
  164. 506. Which two workforce groups does NIST specifically say a learning plan should provide for? Choose two.
  165. 507. An organisation with an existing learning programme wants to reshape it. Which analysis does NIST recommend first?
  166. 508. NIST separates policy from procedure by function. Which pairing is correct?
  167. 509. Which two benefits does NIST attribute to establishing learning programme policies and procedures? Choose two.
  168. 510. Which policy pattern does NIST describe for enforcing awareness training completion?
  169. 511. When does NIST's example policy require role-based training for staff with significant security responsibilities?
  170. 512. An organisation allows exceptions to its training requirement but does not say who may grant them. Which element does NIST's example policy include?
  171. 513. Which acronym does NIST recommend as the test for a learning programme's goals, and what does it stand for?
  172. 514. A learning programme sets a goal of reducing susceptibility to social engineering and runs a phishing exercise in support. Which element of the strategy model is the exercise?
  173. 515. A review finds several learning activities that cannot be traced to any stated objective or goal. What does NIST say about such activities?
  174. 516. An organisation measures its learning programme purely by regulatory completion rates. Which three further effects does NIST say must also be measured?
  175. 517. Why does NIST treat training records as carrying heightened sensitivity?
  176. 518. Which risks does NIST ask a learning programme manager to identify and manage, beyond the risks the programme teaches about?
  177. 519. NIST distinguishes a learning goal from a learning objective. Which pairing is correct?
  178. 520. What distinguishes a learning outcome from a learning goal in NIST's terms?
  179. 521. A programme tests learners immediately after a course and reports high scores. Which additional measurement does NIST recommend, and what does it show?
  180. 522. Which two longitudinal behaviours does NIST offer as evidence of a learning programme's impact? Choose two.
  181. 523. Which measurement does NIST say demonstrates that staff can actually recognise and report a potential security event, which completion rates cannot show?
  182. 524. Which two organisational changes following technical training does NIST offer as measurements? Choose two.
  183. 525. What did NIST's research find about the learning metrics organisations actually use?
  184. 526. NIST divides the learning audience into three overlapping segments. Which set is correct?
  185. 527. Why does NIST say privileged access account holders receive training beyond the all-user programme?
  186. 528. How does NIST describe the relationship between privileged access holders and those with significant security responsibilities?
  187. 529. Which learning duty does NIST assign to managers in relation to staff with significant security responsibilities?
  188. 530. An employee completes the general awareness module but does not know the specific rules governing the application they use daily. Which managerial duty does NIST identify?
  189. 531. Which two responsibilities does NIST assign to an ordinary system user? Choose two.
  190. 532. Which sequence correctly describes the six phases of the security services life cycle?
  191. 533. Which three activities does NIST place in the initiation phase of the security services life cycle?
  192. 534. An organisation is about to choose a security service provider without knowing what its current environment costs or achieves. Which life cycle phase has been skipped?
  193. 535. Which three outputs does the solution phase of the security services life cycle produce?
  194. 536. A service has gone live and the organisation considers the engagement complete. What does NIST say the operations phase requires?
  195. 537. Which two activities does NIST place in the closeout phase of the security services life cycle? Choose two.
  196. 538. Why does NIST ask programme managers to identify the triggers for a replacement security service in advance?
  197. 539. Which two management tools does NIST name for making a security service provider accountable for results? Choose two.
  198. 540. NIST groups security services into three categories. Which set is correct?
  199. 541. Which two dependencies does NIST identify for operational security services? Choose two.
  200. 542. Two organisations run the same application but select different control mixes. Which two factors does NIST say determine the appropriate blend? Choose two.
  201. 543. Why might the same system warrant different controls in two different organisations, according to NIST?
  202. 544. A decision to outsource a security service is taken purely on cost. Which two consequences does NIST warn may follow? Choose two.
  203. 545. Which two of NIST's six issue categories for acquiring security services are correct? Choose two.
  204. 546. On funding decisions for security services, what does NIST say the focus should be?
  205. 547. An organisation engages an external security provider and finds long-established internal controls no longer make sense. How does NIST characterise this?
  206. 548. Which two questions does NIST include in provider evaluation about past performance? Choose two.
  207. 549. Which two commercial terms does NIST say to understand before signing with a security service provider? Choose two.
  208. 550. A provider's contingency planning policy is weaker than the organisation's own. Which question does NIST direct the organisation to ask?
  209. 551. Which two questions does NIST direct at a provider that will hold the organisation's data alongside other customers'? Choose two.
  210. 552. Which two personnel questions does NIST include in evaluating a security service provider? Choose two.
  211. 553. Which aspect of a provider's own position does NIST say should be evaluated as part of the strategic and mission questions?
  212. 554. Which two organisational considerations does NIST list before selecting a security product? Choose two.
  213. 555. Which two product considerations does NIST list for security product selection? Choose two.
  214. 556. Which two vendor considerations does NIST list for security product selection? Choose two.
  215. 557. Which selection preference does NIST express for security products where an evaluated option exists?
  216. 558. What does NIST say a cost-benefit analysis for security product selection should include, beyond the alternatives under consideration?
  217. 559. Which two roles does NIST include among those involved in selecting security products and services? Choose two.
  218. 560. An organisation begins a security service procurement by comparing vendors' offerings. Which prior step does NIST prescribe?
  219. 561. Which two delivery arrangements does NIST identify for a security service, beyond a commercial provider? Choose two.
  220. 562. What does NIST identify as the purpose of configuration management in security terms?
  221. 563. Which three kinds of change does NIST say the configuration management process covers?
  222. 564. Why does NIST require changes to be tested before implementation?
  223. 565. A manager argues a formal change process is not worth its overhead for a small organisation. Which economic argument does NIST make?
  224. 566. Which two things does the baseline configuration control require an organisation to maintain? Choose two.
  225. 567. A change log records that each change occurred but says nothing about its effect. Which control requirement is unmet?
  226. 568. What standard does the configuration settings control set for how security settings should be configured?
  227. 569. Which two elements does the least functionality control require? Choose two.
  228. 570. NIST notes that many system functions and services are provided by default. What does it ask organisations to do about them?
  229. 571. How does the access restrictions for change control differ from configuration change control?
  230. 572. Which two disciplines does NIST say configuration management interlocks with, beyond risk management? Choose two.
  231. 573. Why does NIST say the configuration management process can only begin after the initial control baseline is selected?
  232. 574. Which definition of security accreditation does NIST give?
  233. 575. A significant change is identified through the configuration management process. What does NIST say must follow?
  234. 576. Which principle does NIST say change management must address so that changes reach production only after being tested and approved?
  235. 577. Which two configuration management responsibilities does NIST assign to the system owner? Choose two.
  236. 578. Which two responsibilities does NIST assign to the configuration control review board? Choose two.
  237. 579. Which two daily configuration management duties does NIST assign to the configuration manager? Choose two.
  238. 580. What is the information systems security officer's role in relation to the configuration control board?
  239. 581. NIST assigns system users a defined role in configuration management. What is it?
  240. 582. Which two sources of change initiation does NIST identify beyond users and system owners? Choose two.
  241. 583. Which two questions does NIST's impact analysis of a change request ask? Choose two.
  242. 584. Which three decisions can conclude a change request under NIST's process?
  243. 585. Which staffing arrangement does NIST recommend for moving an approved change into production, and why?
  244. 586. Which two checks does NIST describe under continuous monitoring within the configuration management process? Choose two.
  245. 587. Which three steps does NIST describe for patch management within the configuration process?
  246. 588. How many steps does the Risk Management Framework have, and what distinguishes the first?
  247. 589. What does categorising a system determine, and what does that determination drive?
  248. 590. An organisation plans to select the baseline first and tailor it as a separate later exercise. How does the RMF define the Select step?
  249. 591. Which three things does the RMF Assess step determine about controls?
  250. 592. What determination does the RMF Authorize step make, and what can it cover?
  251. 593. Which two activities does the RMF Monitor step include beyond assessing control effectiveness? Choose two.
  252. 594. An organisation with an agile delivery model wants to iterate between RMF steps rather than run them once in order. What does SP 800-37 permit?
  253. 595. How does SP 800-37 balance the obligation to perform RMF tasks against organisational flexibility?
  254. 596. A team wants to select, tailor, implement and assess controls progressively as a system is built rather than in a single pass. Is this permitted?
  255. 597. Which two things does SP 800-37 require before an organisation re-enters the RMF at a chosen step? Choose two.
  256. 598. Which three designations does NIST use for controls, and what governs the designation?
  257. 599. Why does SP 800-37 require traceability from each control back to the requirement it satisfies?
  258. 600. Which two organisation-level RMF Prepare tasks does SP 800-37 name? Choose two.
  259. 601. Why does SP 800-37 require common controls to be identified, documented and published?
  260. 602. Which two sources does an organisation-level risk assessment draw on, under SP 800-37? Choose two.
  261. 603. Which architectural question does SP 800-37 give as an example for an organisation-level risk assessment?
  262. 604. Why does SP 800-37 ask risk assessment to account for variability across an organisation?
  263. 605. Which two things does a system security plan contain, according to NIST?
  264. 606. How does NIST characterise system security plans, and what accompanies them for controls not yet in place?
  265. 607. An organisation produces its system security plan as an output of the authorisation process. What sequence does NIST require?
  266. 608. A small organisation assigns one individual to several security planning roles. Which caution does NIST give?
  267. 609. Which two decisions does NIST assign to the information owner? Choose two.
  268. 610. An information owner shares data with a partner organisation and considers protection now the partner's responsibility. What does NIST say?
  269. 611. Which two responsibilities does NIST assign to the system owner in relation to the security plan? Choose two.
  270. 612. Which two things do rules of behaviour do, according to NIST? Choose two.
  271. 613. How does NIST require a user's acceptance of the rules of behaviour to be recorded?
  272. 614. Why does NIST say the acknowledgement of the rules of behaviour matters as much as the text itself?
  273. 615. Which two topics does NIST list as typically covered by rules of behaviour? Choose two.
  274. 616. A drafter proposes to reproduce the entire security policy inside the rules of behaviour. What does NIST advise instead?
  275. 617. Who approves a system security plan before authorisation, and what makes that approval meaningful?
  276. 618. Why must a system and its information be categorised before the security plan is written?
  277. 619. Which two statements about defining a system's security boundary are correct under NIST guidance? Choose two.
  278. 620. How does NIST define a subsystem?
  279. 621. Which two activities does NIST include in tailoring a control baseline? Choose two.
  280. 622. An organisation tailors its control baseline but records only the final control set. Which requirement is unmet?
  281. 623. Which two local conditions does NIST say may be used to tailor a control baseline? Choose two.
  282. 624. How does NIST define a compensating security control?
  283. 625. Which two of the three conditions governing the use of a compensating control does NIST state? Choose two.
  284. 626. A system team decides to substitute a compensating control and records it in their own change log only. Which requirement is unmet?
  285. 627. Which two scopes can a common control cover, according to NIST? Choose two.
  286. 628. To whom does NIST say responsibility for developing, implementing and assessing a common control should be assigned?
  287. 629. Which efficiency does NIST attribute to the common control approach?
  288. 630. What risk does NIST identify as arising from widespread dependence on common controls?
  289. 631. How does NIST recommend common controls be handled across many system security plans?
  290. 632. Which two organisational conditions does NIST say make identification of common controls work? Choose two.
  291. 633. What does scoping guidance provide, and what must the security plan record about its use?
  292. 634. Who must review and approve the application of scoping guidance to a system's controls?
  293. 635. Which two roles does NIST say must be involved in security categorisation, showing it is not a single team's task? Choose two.
  294. 636. On what basis is a system rated low, moderate or high against each security objective?
  295. 637. How does NIST define adequate security?
  296. 638. A minor application runs inside a larger general support system. What does NIST say about its security plan?
  297. 639. Which security planning duty does NIST assign to the chief information officer regarding controls the organisation offers for inheritance?
  298. 640. Which coordination duty does NIST assign to the senior information security officer in security planning?
  299. 641. How does NIST define a system interconnection?
  300. 642. Which two levels of system interconnection does NIST describe? Choose two.
  301. 643. Which specific risk does NIST identify when two systems are interconnected?
  302. 644. What does NIST require before an organisation connects its system to another system?
  303. 645. Which two things does a formal interconnection agreement specify, according to NIST? Choose two.
  304. 646. Why does NIST require each interconnected system's controls to be evaluated against the other's requirements?
  305. 647. Which two purposes does NIST give for maintaining clear lines of communication between interconnected parties? Choose two.
  306. 648. How often does NIST say the security controls on an interconnection should be reviewed?
  307. 649. Two systems with different configurations and control sets are to be interconnected. Why does NIST say the resulting risk must be weighed carefully?
  308. 650. Which four phases make up the life cycle management approach for interconnecting systems?
  309. 651. Which two participants does NIST include in a joint planning team for an interconnection? Choose two.
  310. 652. Which three factors does NIST say the business case for an interconnection should weigh?
  311. 653. Why does NIST say each party should consider reauthorising its system before establishing an interconnection?
  312. 654. Which two items does NIST say an interconnection security agreement contains, beyond the technical and security requirements? Choose two.
  313. 655. Which two matters does a memorandum of understanding for an interconnection settle, according to NIST? Choose two.
  314. 656. Who must sign the memorandum of understanding for an interconnection, and why does it matter?
  315. 657. Why does NIST say interconnection agreements themselves need protection?
  316. 658. Which three outcomes are available to an authorising official reviewing a proposed interconnection?
  317. 659. Under what condition does NIST permit the two interconnection documents to be combined, and what must be preserved?
  318. 660. Which two items does NIST say an interconnection implementation plan must identify? Choose two.
  319. 661. Which two things does NIST say both parties should examine closely when a new interconnection is activated? Choose two.
  320. 662. Which two activities does NIST include in maintaining an established interconnection? Choose two.
  321. 663. Which three things does NIST say a written notice of planned disconnection should describe?
  322. 664. Which two considerations govern the scheduling of a planned disconnection, according to NIST? Choose two.
  323. 665. What must both organisations agree about shared data when an interconnection is disconnected?
  324. 666. Which two conditions does NIST attach to an emergency disconnection performed without written notice? Choose two.
  325. 667. Which two things does NIST require after an emergency disconnection? Choose two.
  326. 668. An interconnection was terminated because of an attack and both parties now wish to restore it. Which two steps does NIST require first? Choose two.
  327. 669. An interconnection has been down for more than ninety days and the parties want to restore it. What does NIST require?
  328. 670. How does NIST relate assessment to measurement in SP 800-55?
  329. 671. Which two kinds of assessment does NIST name alongside risk assessment when evaluating security risk? Choose two.
  330. 672. How does NIST characterise the relationship between programme assessments, control assessments and risk assessment?
  331. 673. Which tension does NIST identify in choosing how many security measures to collect?
  332. 674. Which three methods does NIST name for collecting security data?
  333. 675. NIST describes a simulated phishing test as an example of which data collection method?
  334. 676. What distinguishes observational data in NIST's account of measurement?
  335. 677. Which sampling method gives every item an equal chance of selection, aiming for an unbiased picture?
  336. 678. Which two characteristics does NIST attribute to stratified sampling? Choose two.
  337. 679. Which weakness does NIST identify in systematic sampling?
  338. 680. How does NIST characterise a qualitative assessment in SP 800-55?
  339. 681. An organisation reports that it is at level three on a maturity model. How does NIST classify that number?
  340. 682. Which example does NIST give of a quantitative assessment whose values keep their meaning outside the assessment?
  341. 683. Which results does NIST count as measures for the purposes of SP 800-55?
  342. 684. Which two limitations does NIST attach to qualitative assessment, despite its ease of use? Choose two.
  343. 685. Why does NIST say an organisation should consider its motivations before choosing between quantitative and qualitative assessment?
  344. 686. Which measure does NIST say gives sharper insight into patching performance, and why?
  345. 687. An organisation early in its measurement journey relies on a risk matrix. What progression does NIST describe?
  346. 688. Which three properties does NIST require of meaningful security measures?
  347. 689. How does NIST say measurement strengthens governance?
  348. 690. Which pairing correctly matches metric level to the kind of decision it supports?
  349. 691. Which two characteristics does NIST require of a meaningful metric? Choose two.
  350. 692. What consequence does NIST attribute to poorly chosen quantitative metrics?
  351. 693. Which test does NIST give for deciding whether to keep a quantitative metric?
  352. 694. Why does NIST emphasise keeping metrics consistent over time?
  353. 695. How does NIST relate key risk indicators and key performance indicators to metrics generally?
  354. 696. For evaluating cybersecurity awareness training, which approach does NIST prefer?
  355. 697. Which two conditions does NIST say organisation-level measurement requires? Choose two.
  356. 698. NIST states that security cannot be measured perfectly. Which reason does it give, and what does it advise instead?
  357. 717. An organisation contracts a provider to perform incident detection and response. Which two things does NIST say the contract must define? Choose two.
  358. 718. Which two restrictions does NIST say an incident response provider contract should state? Choose two.
  359. 720. Which risk does NIST attach to engaging an incident response provider, and which deterrent does it name?
  360. 740. Which three uses does the Community Profile give for automatically updated hardware and software inventories?
  361. 755. An organisation delivers role-based training covering technical skills but omitting what each role must do during an incident. Which recommendation is unmet?
  362. 761. Which two aspects of external provider behaviour does the Community Profile say should be monitored? Choose two.
  363. 763. Why does the Community Profile recommend monitoring configurations against security baselines?
  364. 771. Which three sources does the Community Profile name for acquiring vulnerability disclosures about the organisation's own technologies?
  365. 815. Which example does NIST give of an incident type a third party might be authorised to contain automatically on the organisation's behalf?
  366. 831. Which two recommendations does NIST make about communicating with suppliers during recovery? Choose two.
  367. 844. Which CSF 2.0 supply chain outcome addresses the involvement of suppliers in incident work?
  368. 866. Which sequence matches NIST's seven-step contingency planning process?
  369. 867. Where in the system life cycle does NIST place the contingency planning policy and the business impact analysis, and why there?
  370. 870. With which functions does NIST say contingency planning must be coordinated?
  371. 917. Which two less obvious costs does NIST say a contingency budget must cover? Choose two.
  372. 924. Which check does NIST require when evaluating whether an alternate site is adequate?
  373. 929. How does NIST distinguish contingency training from awareness?
  374. 932. Beyond individual duties, which topic does NIST expect contingency training to cover?
  375. 939. Which two things does NIST require of every test and exercise?
  376. 942. To which organisational process does NIST tie contingency plan maintenance?
  377. 970. Which judgement does NIST require after reconstitution?
  378. 974. Which three elements does NIST say a test, training and exercise programme needs to be repeatable rather than ad hoc?
  379. 980. Which by-product does NIST attribute to running a training session?