300-740 · Question #71
Drag and Drop Question Drag and drop the five core functions from the left into the order defined by the NIST Cyber security Framework on the right. Answer:
The correct answer is Identify; Protect; Detect; Respond; Recover. NIST Cybersecurity Framework (CSF) - Core Functions Order The five functions follow a logical incident lifecycle: from knowing your environment, to defending it, to detecting threats, to acting on them, to recovering from them. --- 1. Identify Why first: You cannot protect what…
Question
Drag and Drop Question Drag and drop the five core functions from the left into the order defined by the NIST Cyber security Framework on the right. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Identify
- Protect
- Detect
- Respond
- Recover
Explanation
NIST Cybersecurity Framework (CSF) - Core Functions Order
The five functions follow a logical incident lifecycle: from knowing your environment, to defending it, to detecting threats, to acting on them, to recovering from them.
1. Identify
Why first: You cannot protect what you don't know exists. This function establishes the foundation - inventorying assets, understanding business context, identifying risk, and mapping data flows. Everything downstream depends on this awareness.
Think: "What do we have and what matters?"
2. Protect
Why second: Once you know your assets, you implement safeguards - access controls, encryption, security training, data security, and maintenance policies. Protection is proactive and only meaningful after Identify establishes scope.
Think: "How do we defend what we identified?"
3. Detect
Why third: No protection is perfect. Detect covers continuous monitoring, anomaly detection, and security event logging to discover when protective measures fail or are bypassed.
Think: "How do we know when something goes wrong?"
4. Respond
Why fourth: Detection without response is useless. Respond covers incident response planning, communications, analysis, mitigation, and improvements - actions taken after a threat is detected.
Think: "What do we do when we find a threat?"
5. Recover
Why last: Recovery restores capabilities and services impaired by an incident. It only makes sense after responding to contain/eradicate the threat.
Think: "How do we get back to normal?"
Common Mistakes
| Mistake | Reality |
|---|---|
| Swapping Detect and Protect | Protect is proactive (before incident); Detect is reactive (during/after) |
| Placing Respond before Detect | You can't respond to what you haven't detected |
| Placing Recover before Respond | You must contain the threat before restoring systems |
| Forgetting Identify is #1 | Students sometimes assume protection comes first - but you must inventory before defending |
Memory mnemonic: I P D R R - "I Protect Digital Rights Relentlessly"
Topics
Community Discussion
No community discussion yet for this question.
