nerdexam
GIAC

GSEC · Question #280

Training an organization on possible phishing attacks would be included under which NIST Framework Core guidelines?

The correct answer is D. Protect. Security awareness training on phishing falls under the Protect function of the NIST Cybersecurity Framework, which includes the Awareness and Training category (PR.AT).

Incident Handling, Risk, and Governance

Question

Training an organization on possible phishing attacks would be included under which NIST Framework Core guidelines?

Options

  • ADetect
  • BIdentify
  • CRespond
  • DProtect

How the community answered

(47 responses)
  • A
    11% (5)
  • B
    4% (2)
  • C
    4% (2)
  • D
    81% (38)

Why each option

Security awareness training on phishing falls under the Protect function of the NIST Cybersecurity Framework, which includes the Awareness and Training category (PR.AT).

ADetect

The Detect function covers discovering cybersecurity events after they occur, such as anomaly detection and continuous monitoring, not pre-event training.

BIdentify

The Identify function addresses asset management, governance, and risk assessment to understand organizational context, not workforce training.

CRespond

The Respond function covers actions taken after a cybersecurity incident has been detected, such as incident response planning and communications.

DProtectCorrect

The NIST CSF Protect function contains the PR.AT (Awareness and Training) category, which specifically covers ensuring personnel understand their cybersecurity responsibilities and are trained to recognize threats such as phishing. Training is a proactive, preventive control aligned with the Protect function's goal of limiting the impact of potential cybersecurity events. This is a foundational element of organizational security posture under the framework.

Concept tested: NIST CSF Protect function awareness and training category

Source: https://www.nist.gov/cyberframework/framework

Topics

#NIST CSF#security awareness#phishing#Protect function

Community Discussion

No community discussion yet for this question.

Full GSEC Practice