Exam Questions and CORRECT Answers
Physical devices and systems within the organization are inventoried - CORRECT
ANSWER - Identify
Software platforms and applications within the organization are inventoried - CORRECT
ANSWER - Identify
Organizational communication and data flows are mapped - CORRECT ANSWER -
Identify
External information systems are catalogued - CORRECT ANSWER - Identify
Resources (e.g., hardware, devices, data, time, and software) are prioritized based on their
classification, criticality, and business value - CORRECT ANSWER - Identify
Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders
(e.g., suppliers, customers, partners) are established - CORRECT ANSWER - Identify
Priorities for organizational mission, objectives, and activities are established and communicated
- CORRECT ANSWER - Identify
Resilience requirements to support delivery of critical services are established for all operating
states (e.g. under duress/ attack, during recovery, normal operations) - CORRECT
ANSWER - Identify
Information security roles & responsibilities are coordinated and aligned with internal roles and
external partners - CORRECT ANSWER - Identify
, Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties
obligations, are understood and managed - CORRECT ANSWER - Identify
Cyber threat intelligence and vulnerability information is received from information sharing
forums and sources - CORRECT ANSWER - Identify
Organizational risk tolerance is determined and clearly expressed - CORRECT
ANSWER - Identify
The organization's determination of risk tolerance is informed by its role in critical infrastructure
and sector specific risk analysis - CORRECT ANSWER - Identify
Suppliers and partners are required by contract to implement appropriate measures designed to
meet the objectives of the Information Security program or Cyber Supply Chain Risk
Management Plan. - CORRECT ANSWER - Identify
Suppliers and partners are monitored to confirm that they have satisfied their obligations as
required. Reviews of audits, summaries of test results, or other equivalent evaluations of
suppliers/providers are conducted - CORRECT ANSWER - Identify
Response and recovery planning and testing are conducted with critical suppliers/providers -
CORRECT ANSWER - Identify
Identities and credentials are issued, managed, revoked, and audited for authorized devices,
users, and processes - CORRECT ANSWER - Protect
Physical access to assets is managed and protected - CORRECT ANSWER - Protect
Remote access is managed - CORRECT ANSWER - Protect