D-CSF-SC-01 Exam Questions
227 real D-CSF-SC-01 exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51
The primary goal of the COBIT 2019 governance system is to ensure that ___ aligns with the overall business strategy.
- Question #52
The ___________ component of the Detect Function is responsible for identifying unusual patterns or activities that may indicate a threat.
- Question #53
Tiers in the NIST Cybersecurity Framework help organizations assess their level of ___.
- Question #54
An organization is creating a customized version of the NIST Cybersecurity Framework to align with its unique risk profile and business requirements. They are currently mapping the...
- Question #55
Match each Detect Function component with its primary purpose. Component Continuous Monitoring Anomalies and Events Detection Processes Threat Intelligence Purpose
- Question #56
Which protective technologies are typically associated with the Protect Function? (Select two)
- Question #57
What is the primary purpose of the COBIT 2019 governance framework in the context of cybersecurity?
- Question #58
COBIT 2019's focus on cybersecurity risk aligns with which NIST Cybersecurity Framework component?
- Question #59
The ___ function of the NIST Cybersecurity Framework ensures timely identification of cybersecurity events.
- Question #60
Which of the following are key components of an Incident Response Plan? (Select two)
- Question #61
What categories are specifically contained within the Identify function?
- Question #62
What is the main goal of a gap analysis in the Identify function?
- Question #63
How does the COBIT 2019 Framework assist organizations in managing cybersecurity risks?
- Question #64
The __________ process ensures that businesses can continue essential operations with minimal interruption after a cybersecurity incident.
- Question #65
Which COBIT 2019 component aligns most closely with the "Respond" function of the NIST Cybersecurity Framework?
- Question #66
How does COBIT 2019 enhance the implementation of the NIST Cybersecurity Framework?
- Question #67
An organization is creating a disaster recovery plan. They want to ensure all critical assets are accounted for and prioritized. Which component of the Identify Function should the...
- Question #68
The Identify Function helps establish a ___________ to assess and categorize organizational assets by their importance.
- Question #69
What does the Identify Function facilitate in the context of Disaster Recovery and Incident Response planning?
- Question #70
Which document is designed to limit damage, reduce recovery time, and reduce costs where possible to the organization?
- Question #71
The Disaster Recovery Plan must document what effort in order to address unrecoverable assets?
- Question #72
Which mechanism within the NIST Cybersecurity Framework describes a method to capture the current state and define the target state for understanding gaps, exposure, and prioritize...
- Question #73
Which of the following are benefits of implementing continuous monitoring within the Detect Function? (Select two)
- Question #74
In the NIST Cybersecurity Framework, which of the following components is key to ensuring continuity in critical functions after a cybersecurity event?
- Question #75
The NIST Cybersecurity Framework relies on which of the following to guide organizations through effective cybersecurity risk management?
- Question #76
Match the following components of the Identify Function with their main purpose. Component Asset Inventory Risk Assessment Classification Controls Business Impact Analysis Purpose
- Question #77
COBIT 2019 complements the NIST Cybersecurity Framework by focusing on what aspect of cybersecurity risk management?
- Question #78
Which NIST Cybersecurity Framework function should be executed before any others?
- Question #79
An organization has a policy to respond "ASAP" to security incidents. The security team is having a difficult time prioritizing events because they are responding to all of them, i...
- Question #80
One of the five core functions in the NIST Cybersecurity Framework is ___, which focuses on minimizing the impact of cybersecurity events.
- Question #81
Which function of the NIST Cybersecurity Framework focuses on ensuring the organization is able to identify and contain the impact of cybersecurity incidents?
- Question #82
A key consideration in implementing a Disaster Recovery Plan (DRP) is the __________, which defines how quickly systems need to be restored.
- Question #83
Within the Protect Function, ___________ involves limiting access to only those individuals who need it for their work.
- Question #84
What process is used to identify an organization's physical, digital, and human resource, as required in their Business Impact Analysis?
- Question #85
In which function is the SDLC implemented?
- Question #86
Which function of the NIST Cybersecurity Framework should be prioritized first in building a cybersecurity strategy?
- Question #87
Match each Protect Function subcategory with its main focus. Subcategory Data Security Awareness Training Protective Technology Baseline Configuration Focus
- Question #88
In COBIT 2019, which design factor is essential for tailoring the implementation of the NIST Cybersecurity Framework to an organization's needs?
- Question #89
The network security team in your company has discovered a threat that leaked partial data on a compromised file server that handles sensitive information. Containment must be init...
- Question #90
Your firewall blocked several machines on your network from connecting to a malicious IP address. After reviewing the logs, the CSIRT discovers all Microsoft Windows machines on th...
- Question #91
Which NIST Cybersecurity Framework category ensures that organizational communication and data flows are mapped?
- Question #92
Unrecoverable assets are specifically addressed in which function?
- Question #93
Consider the following situation: - A complete service outage has occurred, affecting critical services - Users are unable to perform their tasks - Customers are unable to conduct...
- Question #94
A business needs a high-level view to understand its current cybersecurity activities and align these with industry standards. The business also wants a roadmap for future improvem...
- Question #95
The ___ profile in the NIST Cybersecurity Framework represents the desired cybersecurity outcomes aligned with the organization's risk tolerance.
- Question #96
A company has just acquired an intrusion detection system (IDS) whose detection capabilities are based on behavior and baselines. The IDS has not been in production long enough to...
- Question #97
What is used to ensure an organization understands the security risk to operations, assets, and individuals?
- Question #98
Refer to the exhibit. What is shown?
- Question #99
When gaps are found during the ___ process, they are used to create the action plan for addressing cybersecurity risks.
- Question #100
To generate an accurate risk assessment, organizations need to gather information in what areas?